CVE-2021-29060

Related Vulnerabilities: CVE-2021-29060  

A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Color-String version 1.5.5 and below which occurs when the application is provided and checks a crafted invalid HWB string.

Description

The MITRE CVE dictionary describes this issue as:

A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in Color-String version 1.5.5 and below which occurs when the application is provided and checks a crafted invalid HWB string.

Additional Information

  • Bugzilla 1974848: CVE-2021-29060 nodejs-color-string: Regular expression denial of service when the application is provided and checks a crafted invalid HWB string
  • CWE-400: Uncontrolled Resource Consumption
  • FAQ: Frequently asked questions about CVE-2021-29060