CVE-2021-36716: High severity segment is-email vulnerability
A ReDoS (regular expression denial of service) flaw was found in the Segment is-email package before 1.0.1 for Node.js. An attacker that is able to provide crafted input to the isEmail(input) function may cause an application to consume an excessive amount of CPU.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-36716?
CVE-2021-36716 has a medium severity due to its potential to cause denial of service by consuming excessive CPU resources.
How do I fix CVE-2021-36716?
To fix CVE-2021-36716, you should update the Segment is-email package to version 1.0.1 or later.
What is the impact of CVE-2021-36716 on applications?
The impact of CVE-2021-36716 can result in application performance degradation due to high CPU usage when processing malicious input.
Who is affected by CVE-2021-36716?
CVE-2021-36716 affects applications utilizing the Segment is-email package version prior to 1.0.1 in Node.js.
What type of vulnerability is CVE-2021-36716?
CVE-2021-36716 is classified as a ReDoS (regular expression denial of service) vulnerability.