The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Autoshare For Twitter Plugin | — | Update autoshare-for-twitter plugin to version 1.2.0, or a newer patched version | May 15, 2025 | Jul 15, 2022 |
| Debian | — | Upgrade node-terser | Jul 30, 2024 | Jul 15, 2022 |
| Elasticpress Plugin | — | Update elasticpress plugin to version 4.3.0, or a newer patched version | May 15, 2025 | Jul 14, 2022 |
| Maps Block Apple Plugin | — | Update maps-block-apple plugin to version 1.1.0, or a newer patched version | May 15, 2025 | Jul 15, 2022 |
| Publisher Media Kit Plugin | — | Update publisher-media-kit plugin to version 1.3.0, or a newer patched version | May 15, 2025 | Jul 15, 2022 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Jul 15, 2022 |
| Retro Winamp Block Plugin | — | Update retro-winamp-block plugin to version 1.2.0, or a newer patched version | May 15, 2025 | Jul 15, 2022 |
| Simple Local Avatars Plugin | — | Update simple-local-avatars plugin to version 2.6.0, or a newer patched version | May 15, 2025 | Jul 14, 2022 |
| Simple Podcasting Plugin | — | Update simple-podcasting plugin to version 1.2.4, or a newer patched version | May 15, 2025 | Jul 14, 2022 |
| Sophi Plugin | — | Update sophi plugin to version 1.2.1, or a newer patched version | May 15, 2025 | Jul 14, 2022 |
| Splunk | — | Upgrade Splunk Enterprise to version 8.1.14Upgrade Splunk Enterprise to version 8.2.11Upgrade Splunk Enterprise to version 9.0.5 | Sep 30, 2025 | Jul 15, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub