i18next / i18next-http-backend

i18next-http-backend is a backend layer for i18next using in Node.js, in the browser and for Deno.
MIT License
443 stars 67 forks source link

PSIRT PVR0377943: node-fetch-2.6.7[Due Date: 2022-08-18] #95

Closed PAnilReddy closed 2 years ago

PAnilReddy commented 2 years ago

Summary: Denial of Service in GitHub repository node-fetch/node-fetch prior to 3.2.10.

Details: nodejs-cve20222596-dos (232616) - reported on 2022-07-31 (Format: yyyy-mm-dd)

Node.js node-fetch module is vulnerable to a denial of service, caused by a regular expression denial of service (ReDoS) flaw in the isOriginPotentiallyTrustworthy() function in the referrer.js script. By sending specially-crafted regex input, a remote attacker could exploit this vulnerability to cause a denial of service.

Consequences: Denial of Service

Remedy: Upgrade to the latest version of Node.js node-fetch module (3.2.10 or later), available from the NPM Web site. See References.

and plans of updating the version to latest

adrai commented 2 years ago

https://github.com/i18next/i18next-http-backend/issues/93