Back

HIGH

The csv-parse module before 4.4.6 for Node.js is vulnerable to Regular Expression Denial of Service

Published Oct 14, 2019

Description

The csv-parse module before 4.4.6 for Node.js is vulnerable to Regular Expression Denial of Service. The __isInt() function contains a malformed regular expression that processes large crafted input very slowly. This is triggered when using the cast option.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (7)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 14, 2019
Updated Aug 5, 2024
Reserved Oct 14, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
GHSA-582F-P4PG-XC74