Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Regular Expression Denial of Service (ReDoS)
Vulnerability Description
This affects the package html-parse-stringify before 2.0.1; all versions of package html-parse-stringify2. Sending certain input could cause one of the regular expressions that is used for parsing to backtrack, freezing the process.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Vulnerability Type
N/A
Vulnerability Title
html-parse-stringify 安全漏洞
Vulnerability Description
Henrik Joreteg html-parse-stringify是 (Henrik Joreteg)开源的一个应用软件。提供了一种可以快速将HTML解析为AST并将其字符串化为原始字符串的方法。 html-parse-stringify before 2.0.1 存在安全漏洞,该漏洞源于发送某些输入可能会导致用于解析的某个正则表达式回溯、冻结进程。
CVSS Information
N/A
Vulnerability Type
N/A