{"id":"CVE-2025-2792","aliases":[],"url":"https://o3.security/vulnerability/CVE-2025-2792","summary":"@mozilla/readability Denial of Service through Regex","details":"Specially crafted titles may have caused a regular expression to excessively backtrack and cause a local denial of service.\n\nAdditional Details are [available at Bugzilla](https://bugzilla.mozilla.org/show_bug.cgi?id=1948833)\n\nCredit: DayShift","published":"2025-03-26T14:08:48Z","modified":"2025-03-26T14:30:14.211850Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"@mozilla/readability","fixedVersion":"0.6.0"}],"fix":{"url":"https://github.com/mozilla/readability/commit/1c4d63be3e7344c3dfdf76ebb05fd0d32de93eb3","label":"mozilla/readability@1c4d63b"},"references":[{"type":"WEB","url":"https://github.com/mozilla/readability/security/advisories/GHSA-3p6v-hrg8-8qj7"},{"type":"WEB","url":"https://github.com/mozilla/readability/commit/1c4d63be3e7344c3dfdf76ebb05fd0d32de93eb3"},{"type":"WEB","url":"https://bugzilla.mozilla.org/show_bug.cgi?id=1948833"},{"type":"PACKAGE","url":"https://github.com/mozilla/readability"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-03-26T14:30:14.211850Z"}}