All versions of package trim are vulnerable to Regular Expression Denial of Service (ReDoS) via trim().
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Dell Powerstore Dsa2023366 | — | Upgrade Dell PowerStoreOS to the latest version | Oct 23, 2025 | Oct 5, 2023 |
| Splunk | — | Upgrade Splunk Enterprise to version 8.1.14Upgrade Splunk Enterprise to version 9.0.5Upgrade Splunk Enterprise to version 8.2.11 | Sep 30, 2025 | Oct 27, 2020 |
| Suse | — | Upgrade libisccfg1600-32bitUpgrade libdns1605Upgrade bind-develUpgrade bind-chrootenvUpgrade bind-devel-32bitUpgrade bindUpgrade golang-github-lusitaniae-apache_exporterUpgrade python3-bindUpgrade libns1604-32bitUpgrade libisccc1600Upgrade prometheus-postgres_exporterUpgrade libisccc1600-32bitUpgrade libirs-develUpgrade libdns1605-32bitUpgrade libirs1601-32bitUpgrade bind-docUpgrade wireUpgrade spacecmdUpgrade libirs1601Upgrade dracut-saltbootUpgrade libbind9-1600-32bitUpgrade libisc1606Upgrade libns1604Upgrade bind-utilsUpgrade libbind9-1600Upgrade grafanaUpgrade libisc1606-32bitUpgrade libisccfg1600 | Aug 9, 2024 | Oct 27, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub