Vulnerability GHSA-cwfw-4gq5-mrqx
Low Risk
LOW RISK
CVSS Score: 3.0
Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
4 years ago
January 06, 2022 at 08:42 PM UTC
Regular Expression Denial of Service (ReDoS) in braces
2.2.0 - 2.3.0
2.2.0 - 2.3.0
Summary
Regular Expression Denial of Service (ReDoS) in braces
Details
A vulnerability was found in Braces versions from v2.2.0 up to but not including v2.3.1. Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) attacks. This has been patched in version 2.3.1.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
14 days ago
braces vulnerable to stack-exhaustion denial of service through deeply nested patterns
0.1.0 - 3.0.3 GHSA-vfj7-8cjw-p6xm
0.1.0 - 3.0.3 GHSA-vfj7-8cjw-p6xm
High Risk
2 years ago
Uncontrolled resource consumption in braces
0.1.0 - 3.0.2 GHSA-grv7-fg5c-xmjg
0.1.0 - 3.0.2 GHSA-grv7-fg5c-xmjg
Impacted packages
Timeline
Published
4 years ago
January 06, 2022 at 08:42 PM UTC
Fixed (2.3.1)
8 years ago
February 18, 2018 at 04:16 AM UTC
Last Modified
10 months ago
November 26, 2025 at 05:32 PM UTC