{"id":"GHSA-xx4c-jj58-r7x6","aliases":[],"url":"https://o3.security/vulnerability/GHSA-xx4c-jj58-r7x6","summary":"Inefficient Regular Expression Complexity in Validator.js","details":"### Impact\nVersions of `validator` prior to 13.7.0 are affected by an inefficient Regular Expression complexity  when using the `rtrim` and `trim` sanitizers.\n\n### Patches\nThe problem has been patched in validator 13.7.0","published":"2021-11-19T20:14:23Z","modified":"2022-07-12T00:11:53Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"validator","fixedVersion":"13.7.0"}],"fix":{"url":"https://github.com/validatorjs/validator.js/pull/1738","label":"validatorjs/validator.js#1738"},"references":[{"type":"WEB","url":"https://github.com/validatorjs/validator.js/security/advisories/GHSA-xx4c-jj58-r7x6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-3765"},{"type":"WEB","url":"https://github.com/validatorjs/validator.js/issues/1599"},{"type":"WEB","url":"https://github.com/validatorjs/validator.js/pull/1738"},{"type":"PACKAGE","url":"https://github.com/validatorjs/validator.js"},{"type":"WEB","url":"https://huntr.dev/bounties/c37e975c-21a3-4c5f-9b57-04d63b28cfc9"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2022-07-12T00:11:53Z"}}