CVE-2023-26115: High severity Word-wrap Project Word-wrap Node.js vulnerability
A flaw was found in the Node.js word-wrap module, where it is vulnerable to a denial of service caused by a Regular expression denial of service (ReDoS) issue in the result variable. By sending a specially crafted regex input, a remote attacker can cause a denial of service.
Other sources
All versions of the package word-wrap are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of an insecure regular expression within the result variable.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/word-wrapto a version that resolves this vulnerability.Fixed in 1.2.4 - Upgrade
Upgrade
redhat/word-wrapto a version that resolves this vulnerability.Fixed in 1.2.4 - Upgrade
Upgrade
word-wrapto a version that resolves this vulnerability.Patch SNYK-JS-WORDWRAP-3149973 - Compensating control
Mitigate the ReDoS denial-of-service risk by preventing remote attackers from sending specially crafted inputs to the word-wrap functionality until the vulnerable version is patched.
Event History
Parent advisories
This vulnerability appears in the following advisories.