{"id":"CVE-2019-1010266","aliases":["GHSA-x5rq-j2xg-h7qm","SNYK-JS-LODASH-73639"],"url":"https://o3.security/vulnerability/CVE-2019-1010266","summary":"Regular Expression Denial of Service (ReDoS) in lodash","details":"lodash prior to 4.17.11 is affected by: CWE-400: Uncontrolled Resource Consumption. The impact is: Denial of service. The component is: Date handler. The attack vector is: Attacker provides very long strings, which the library attempts to match using a regular expression. The fixed version is: 4.17.11.","published":"2019-07-17T21:15:10.873Z","modified":"2026-07-09T01:06:42.570784Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"lodash","fixedVersion":"4.17.11"},{"ecosystem":"npm","name":"lodash-es","fixedVersion":"4.17.11"},{"ecosystem":"npm","name":"lodash-amd","fixedVersion":"4.17.11"},{"ecosystem":"RubyGems","name":"lodash-rails","fixedVersion":"4.17.11"}],"fix":{"url":"https://github.com/github/advisory-database/pull/6138","label":"github/advisory-database#6138"},"references":[{"type":"ADVISORY","url":"https://github.com/lodash/lodash/wiki/Changelog"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20190919-0004/"},{"type":"REPORT","url":"https://github.com/lodash/lodash/issues/3359"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JS-LODASH-73639"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-1010266"},{"type":"WEB","url":"https://github.com/github/advisory-database/pull/6138"},{"type":"WEB","url":"https://github.com/lodash/lodash/commit/5c08f18d365b64063bfbfa686cbb97cdd6267347"},{"type":"PACKAGE","url":"https://github.com/lodash/lodash"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/lodash-rails/CVE-2019-1010266.yml"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20190919-0004"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T01:06:42.570784Z"}}