The ms package prior to 0.7.1 for Node.js allows malicious users to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)."
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
vercel ms |