First published: Mon Aug 01 2022(Updated: )
Inefficient Regular Expression Complexity in GitHub repository node-fetch/node-fetch prior to 3.2.10.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
Node-fetch Project Node-fetch | >=3.0.0<3.2.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2596 is a vulnerability in the GitHub repository node-fetch/node-fetch prior to version 3.2.10, that is related to inefficient regular expression complexity.
The severity of CVE-2022-2596 is medium with a CVSS score of 5.9.
CVE-2022-2596 affects Node-fetch Project Node-fetch versions between 3.0.0 and 3.2.10.
To fix CVE-2022-2596, update Node-fetch Project Node-fetch to version 3.2.10 or later.
You can find more information about CVE-2022-2596 at the following references: [GitHub Commit](https://github.com/node-fetch/node-fetch/commit/28802387292baee467e042e168d92597b5bbbe3d), [Huntr Bounty](https://huntr.dev/bounties/a7e6a136-0a4b-46c4-ad20-802f1dd60bf7).