CVE-2020-28500 PUBLISHED

Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.

EPSS 0.25% · 47.6th percentile

Risk Scores

EPSS Score
0.25%
47.6th percentile

Affected Products

VendorProductVersions
Ubuntu:20.04:LTSnode-lodash0, 4.17.15+dfsg-2, 4.17.11+dfsg-4
Ubuntu:24.04:LTSnode-lodash4.17.21+dfsg+~cs8.31.198.20210220-9, 0
Ubuntu:18.04:LTSnode-lodash4.17.4+dfsg-1, 0
Ubuntu:25.10node-lodash*, 0
Oracle Cloudfunctions
Ubuntu:16.04:LTSnode-lodash0, 2.4.1+dfsg-3
Azurefunctions
Ubuntu:22.04:LTSnode-lodash*, 4.17.21+dfsg+~cs8.31.198.20210220-5, 4.17.21+dfsg+~cs8.31.198.20210220-4

Timeline

References

Open in Interactive Console →