CVE-2021-3765: Inefficient Regular Expression Complexity in validatorjs/validator.js
validator.js is vulnerable to Inefficient Regular Expression Complexity
Other sources
validator.js prior to 13.7.0 is vulnerable to Inefficient Regular Expression Complexity
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/validatorto a version that resolves this vulnerability.Fixed in 13.7.0 - Upgrade
Upgrade
redhat/validatorto a version that resolves this vulnerability.Fixed in 13.7.0
Event History
Frequently Asked Questions
What is the severity of CVE-2021-3765?
CVE-2021-3765 is rated as a moderate severity vulnerability due to its potential for denial of service caused by inefficient regular expression complexity.
How do I fix CVE-2021-3765?
To fix CVE-2021-3765, you should update validator.js to version 13.7.0 or later.
What impact does CVE-2021-3765 have on applications?
CVE-2021-3765 can lead to application performance issues or denial of service due to excessive resource consumption.
Which versions of validator.js are affected by CVE-2021-3765?
CVE-2021-3765 affects all versions of validator.js prior to version 13.7.0.
Who is responsible for the CVE-2021-3765 vulnerability?
The CVE-2021-3765 vulnerability has been reported by the Validator Project, which maintains the validator.js library.