CVE-2021-36716
Improper Input Validation in is-email
7.5
HIGH
CVSS 3.1
EPSS 0.47%
Description
is-email helps validate an email address. A ReDoS (regular expression denial of service) flaw was found in the Segment is-email package before 1.0.1 for Node.js. An attacker that is able to provide crafted input to the isEmail(input) function may cause an application to consume an excessive amount of CPU.
How to fix CVE-2021-36716
To remediate CVE-2021-36716, upgrade the affected package to a fixed version below.
- —upgrade to 1.0.1 or later
Is CVE-2021-36716 being exploited?
Low — EPSS is 0.5%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.0.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |