{"id":"CVE-2021-23354","aliases":["GHSA-xfhp-gmh8-r8v2","SNYK-JS-PRINTF-1072096"],"url":"https://o3.security/vulnerability/CVE-2021-23354","summary":"printf vulnerable to Regular Expression Denial of Service (ReDoS)","details":"The package printf before 0.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the regex string /\\%(?:\\(([\\w_.]+)\\)|([1-9]\\d*)\\$)?([0 +\\-\\]*)(\\*|\\d+)?(\\.)?(\\*|\\d+)?[hlL]?([\\%bscdeEfFgGioOuxX])/g in lib/printf.js. The vulnerable regular expression has cubic worst-case time complexity.","published":"2021-03-12T15:15:14.207Z","modified":"2026-07-09T14:44:00.871005Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"printf","fixedVersion":"0.6.1"}],"fix":{"url":"https://github.com/adaltas/node-printf/pull/32","label":"adaltas/node-printf#32"},"references":[{"type":"ADVISORY","url":"https://snyk.io/vuln/SNYK-JS-PRINTF-1072096"},{"type":"REPORT","url":"https://github.com/adaltas/node-printf/issues/31"},{"type":"FIX","url":"https://github.com/adaltas/node-printf/pull/32"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T14:44:00.871005Z"}}