Uncontrolled Resource Consumption in ansi-html
High severity
GitHub Reviewed
Published
Sep 2, 2021
to the GitHub Advisory Database
•
Updated Nov 28, 2023
Description
Published by the National Vulnerability Database
Aug 18, 2021
Reviewed
Aug 26, 2021
Published to the GitHub Advisory Database
Sep 2, 2021
Last updated
Nov 28, 2023
This affects all versions of package ansi-html. If an attacker provides a malicious string, it will get stuck processing the input for an extremely long time.
References