CVE-2022-25887: Regular Expression Denial of Service (ReDoS)
A flaw was found in sanitize-html library. Insecure global regular expression replacement logic of HTML comment removal could lead to a regular expression Denial of Service (ReDoS), affecting the availability of the affected component.
Other sources
A Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal.
Reference:
https://security.snyk.io/vuln/SNYK-JS-SANITIZEHTML-2957526 https://github.com/apostrophecms/sanitize-html/pull/557 https://github.com/apostrophecms/sanitize-html/commit/b4682c12fd30e12e82fa2d9b766de91d7d2cd23c
— Red Hat
Node.js sanitize-html module is vulnerable to a denial of service, caused by insecure global regular expression replacement logic of HTML comment removal. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause a Regular Expression Denial of Service (ReDoS).
— IBM
The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-25887.
What is the severity of CVE-2022-25887?
The severity of CVE-2022-25887 is high with a CVSS score of 7.5.
Which software packages are affected by CVE-2022-25887?
The sanitize-html package before version 2.7.1 is affected by CVE-2022-25887.
What is the impact of CVE-2022-25887?
CVE-2022-25887 can be exploited by a remote attacker to cause a Regular Expression Denial of Service (ReDoS).
How can I fix CVE-2022-25887?
To fix CVE-2022-25887, update the sanitize-html package to version 2.7.1 or later.