Terser < 4.8.1 and 5.0.0-5.14.1 - Regular Expression Denial of Service
mediumThe package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions. As this package is used in some WordPress plugins, this could result in the impacted plugins being vulnerable.
- CVSS:
- 5.3
- Affected:
- up to 1.2.1
- Fixed in:
- 1.3.0
- Disclosed:
- Jul 15, 2022