CVE-2020-36649

HIGH7.5EPSS 0.43%

Regular Expression Denial of Service in papaparse

Published: 9/4/2020Modified: 6/16/2025
Also known as:GHSA-qvjc-g5vr-mfgrDEBIAN-CVE-2020-36649

Description

Versions of `papaparse` prior to 5.2.0 are vulnerable to Regular Expression Denial of Service (ReDos). The `parse` function contains a malformed regular expression that takes exponentially longer to process non-numerical inputs. This allows attackers to stall systems and lead to Denial of Service. ## Recommendation Upgrade to version 5.2.0 or later.

Affected packages (2)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1HIGH7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

References (10)