{"id":"CVE-2021-33502","aliases":["GHSA-px4h-xg32-q955"],"url":"https://o3.security/vulnerability/CVE-2021-33502","summary":"ReDoS in normalize-url","details":"The normalize-url package before 4.5.1, 5.x before 5.3.1, and 6.x before 6.0.1 for Node.js has a ReDoS (regular expression denial of service) issue because it has exponential performance for data: URLs.","published":"2021-05-24T16:15:08.133Z","modified":"2026-07-08T06:02:34.705646636Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"normalize-url","fixedVersion":"4.5.1"},{"ecosystem":"npm","name":"normalize-url","fixedVersion":"5.3.1"},{"ecosystem":"npm","name":"normalize-url","fixedVersion":"6.0.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/sindresorhus/normalize-url/releases/tag/v6.0.1"},{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20210706-0001/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-08T06:02:34.705646636Z"}}