{"id":"GHSA-36jr-mh4h-2g58","aliases":[],"url":"https://o3.security/vulnerability/GHSA-36jr-mh4h-2g58","summary":"d3-color vulnerable to ReDoS","details":"The d3-color module provides representations for various color spaces in the browser. Versions prior to 3.1.0 are vulnerable to a Regular expression Denial of Service. This issue has been patched in version 3.1.0. There are no known workarounds.","published":"2022-09-29T14:12:55Z","modified":"2026-09-10T03:49:55.734654222Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"d3-color","fixedVersion":"3.1.0"}],"fix":{"url":"https://github.com/d3/d3-color/pull/100","label":"d3/d3-color#100"},"references":[{"type":"WEB","url":"https://github.com/d3/d3-color/pull/100"},{"type":"PACKAGE","url":"https://github.com/d3/d3-color"},{"type":"WEB","url":"https://github.com/d3/d3-color/releases/tag/v3.1.0"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-D3COLOR-1076592"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-10T03:49:55.734654222Z"}}