logo
Vulnerability feed
CONTRIBUTE

Vulnerability

warn

CVE-2022-25883

Reference to the description:

https://nvd.nist.gov/vuln/detail/CVE-2022-25883

Description:
Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.
Last updated date:
12/06/2024
Type:
exploit
Confidence:
HIGH
Date of publishing:
07/05/2023
Reference url to background

https://security.snyk.io/vuln/SNYK-JS-SEMVER-3247795

Vulnerability FeedContributorsAboutBlog

@inTheWild

©2025

Privacy Policy