CVE-2022-37620

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
31/10/2022
Last modified:
01/06/2025

Description

A Regular Expression Denial of Service (ReDoS) flaw was found in kangax html-minifier 4.0.0 because of the reCustomIgnore regular expression.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:terser:html-minifier-terser:*:*:*:*:*:node.js:*:* 7.2.0 (including)
cpe:2.3:a:kangax:html-minifier:*:*:*:*:*:node.js:*:* 4.0.0 (including)