Skip to main content

Inefficient Regular Expression Complexity

CVE-2018-25077

Severity High
Score 7.5/10

Summary

A vulnerability was found in mel-spintax versions prior to 1.0.3. It has been rated as problematic. Affected by this issue is some unknown functionality of the file "lib/spintax.js". The manipulation of the argument text leads to inefficient regular expression complexity. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-218456.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • HIGH

CWE-1333 - Inefficient Regular Expression Complexity

The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.

References

Advisory Timeline

  • Published