VDB
DEBIAN-CVE-2022-25858
DEBIAN-CVE-2022-25858
PUBLISHED
CVSS 7.5 HIGH
The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Debian:11 | node-terser | 5.16.1-1, 5.16.3-1, 5.15.1-1 |
| Debian:12 | node-terser | 0, 0, 0 |
| Debian:13 | node-terser | 0, 0, 0 |
| Debian:14 | node-terser | 0, 0, 0 |
Timeline
- Jul 15, 2022 CVE Published
- Apr 28, 2026 CVE Updated