{"id":"CVE-2022-35923","aliases":["GHSA-xrx9-gj26-5wx9"],"url":"https://o3.security/vulnerability/CVE-2022-35923","summary":"Inefficient Regular Expression Complexity in v8n","details":"v8n is a javascript validation library. Versions of v8n prior to 1.5.1 were found to have an inefficient regular expression complexity in the `lowercase()` and `uppercase()` regex which could lead to a denial of service attack. In testing of the `lowercase()` function a payload of 'a' + 'a'.repeat(i) + 'A' with 32 leading characters took 29443 ms to execute. The same issue happens with uppercase(). Users are advised to upgrade. There are no known workarounds for this issue.","published":"2022-08-02T20:10:11Z","modified":"2026-08-12T03:51:29.824350140Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":1,"affectedPackages":[{"ecosystem":"npm","name":"v8n","fixedVersion":"1.5.1"}],"fix":{"url":"https://github.com/imbrn/v8n/commit/92393862156fad190c05ec3f6e2bc73308dcd2f9","label":"imbrn/v8n@9239386"},"references":[{"type":"WEB","url":"https://huntr.dev/bounties/2d92f644-593b-43b4-bfd1-c8042ac60609/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/35xxx/CVE-2022-35923.json"},{"type":"ADVISORY","url":"https://github.com/imbrn/v8n/security/advisories/GHSA-xrx9-gj26-5wx9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-35923"},{"type":"FIX","url":"https://github.com/imbrn/v8n/commit/92393862156fad190c05ec3f6e2bc73308dcd2f9"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:29.824350140Z"}}