ansman / validate.js

A declarative validation library written javascript
https://validatejs.org
MIT License
2.63k stars 336 forks source link

Security Issue: Request for contact #342

Open pwntester opened 3 years ago

pwntester commented 3 years ago

Hello,

The GitHub Security Lab team has found a potential vulnerability in your project. Please create a Security Advisory and invite me in to further disclose and discuss the vulnerability details and potential fix. Alternatively, please add a Security Policy containing a security email address to send the details to.

Kind regards, A

MichalGorskiOnegini commented 3 years ago

Hey @pwntester, did anyone respond to you?

pwntester commented 3 years ago

@MichalGorskiOnegini no one yet

MichalGorskiOnegini commented 3 years ago

Thanks. I think the project is dead, unfortunately. What type of vulnerability is that? I'm about to use this in production code, but your comment made me worried.

pwntester commented 3 years ago

Sorry for the late response, this is a ReDOS vulnerability