{"id":"GHSA-h6ch-v84p-w6p9","aliases":[],"url":"https://o3.security/vulnerability/GHSA-h6ch-v84p-w6p9","summary":"Regular Expression Denial of Service (ReDoS)","details":"A vulnerability was found in diff before v3.5.0, the affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) attacks.","published":"2019-06-13T18:58:54Z","modified":"2026-02-04T04:02:09.322624Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"diff","fixedVersion":"3.5.0"}],"fix":{"url":"https://github.com/kpdecker/jsdiff/commit/2aec4298639bf30fb88a00b356bf404d3551b8c0","label":"kpdecker/jsdiff@2aec429"},"references":[{"type":"WEB","url":"https://github.com/kpdecker/jsdiff/commit/2aec4298639bf30fb88a00b356bf404d3551b8c0"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1552148"},{"type":"WEB","url":"https://snyk.io/vuln/npm:diff:20180305"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1631"},{"type":"WEB","url":"https://www.whitesourcesoftware.com/vulnerability-database/WS-2018-0590"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-02-04T04:02:09.322624Z"}}