A flaw was found in uri-js versions 2.1.1 and earlier. uri-js uses a regular expression to validate an URL. This regular expression is vulnerable to redos which causes the program to hang and the CPU to idle at 100% usage while uri-js is trying to validate if the supplied URL is valid or not. References: https://github.com/garycourt/uri-js/issues/12 https://nodesecurity.io/advisories/100 Patch: https://github.com/garycourt/uri-js/pull/17
Created nodejs-uri-js tracking bugs for this issue: Affects: fedora-all [bug 1588825]
This CVE Bugzilla entry is for community support informational purposes only as it does not affect a package in a commercially supported Red Hat product. Refer to the dependent bugs for status of those individual community products.