{"id":"CVE-2021-23346","aliases":["GHSA-545q-3fg6-48m7"],"url":"https://o3.security/vulnerability/CVE-2021-23346","summary":"html-parse-stringify and html-parse-stringify2 vulnerable to Regular expression denial of service (ReDoS)","details":"This affects the package html-parse-stringify before 2.0.1; all versions of package html-parse-stringify2. Sending certain input could cause one of the regular expressions that is used for parsing to backtrack, freezing the process.","published":"2021-03-04T17:15:13.700Z","modified":"2026-07-09T00:06:17.426492Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"html-parse-stringify","fixedVersion":"2.0.1"},{"ecosystem":"npm","name":"html-parse-stringify2","fixedVersion":null}],"fix":{"url":"https://github.com/HenrikJoreteg/html-parse-stringify/commit/c7274a48e59c92b2b7e906fedf9065159e73fe12","label":"HenrikJoreteg/html-parse-stringify@c7274a4"},"references":[{"type":"ADVISORY","url":"https://github.com/HenrikJoreteg/html-parse-stringify/blob/master/lib/parse.js%23L2"},{"type":"ADVISORY","url":"https://github.com/rayd/html-parse-stringify2/blob/master/lib/parse.js%23L2"},{"type":"FIX","url":"https://github.com/HenrikJoreteg/html-parse-stringify/commit/c7274a48e59c92b2b7e906fedf9065159e73fe12"},{"type":"FIX","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1080633"},{"type":"FIX","url":"https://snyk.io/vuln/SNYK-JS-HTMLPARSESTRINGIFY-1079306"},{"type":"FIX","url":"https://snyk.io/vuln/SNYK-JS-HTMLPARSESTRINGIFY2-1079307"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T00:06:17.426492Z"}}