VDB

RHBA-2024%3A10760

RHBA-2024%3A10760 PUBLISHED CVSS 4.400000095367432 MEDIUM

A Regular Expression Denial of Service (ReDoS) vulnerability was found in the cross-spawn package for Node.js. Due to improper input sanitization, an attacker can increase CPU usage and crash the program with a large, specially crafted string.

Risk Scores

CVSS 3.1
4.400000095367432
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red Hatrhdh/rhdh-operator-bundle@sha256:1da349194fc014e578fe3d568142769dbbc86212ee030fbcc7fe769f1f16053a_amd64 as a component of Red Hat Developer Hub 1.3 for RHEL 9rhdh/rhdh-operator-bundle@sha256:1da349194fc014e578fe3d568142769dbbc86212ee030fbcc7fe769f1f16053a_amd64
Red Hatrhdh/rhdh-rhel9-operator@sha256:7c8d747bd3a39eebe83a3b88f9136bc1a5c17114550c0db059b7cf74d3d2caf1_amd64 as a component of Red Hat Developer Hub 1.3 for RHEL 9rhdh/rhdh-rhel9-operator@sha256:7c8d747bd3a39eebe83a3b88f9136bc1a5c17114550c0db059b7cf74d3d2caf1_amd64
Red Hatrhdh/rhdh-hub-rhel9@sha256:5173269a9ba82b51d892feb8eaba934340b5defe2f52a20bcacfcca7a81ae6e2_amd64 as a component of Red Hat Developer Hub 1.3 for RHEL 9rhdh/rhdh-hub-rhel9@sha256:5173269a9ba82b51d892feb8eaba934340b5defe2f52a20bcacfcca7a81ae6e2_amd64

Timeline

  • Dec 17, 2024 CVE Published
  • Apr 30, 2026 CVE Updated
  • May 2, 2026 Security Advisory
  • May 2, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›