The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions.
CVSS Details
- CVSS 3.1 Base Score: 5.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Autoshare For Twitter Plugin | autoshare-for-twitter-plugin-cve-2022-25858 | May 15, 2025 | Jul 15, 2022 | |
| Debian | debian-upgrade-node-terser | Jul 30, 2024 | Jul 15, 2022 | |
| Elasticpress Plugin | elasticpress-plugin-cve-2022-25858 | May 15, 2025 | Jul 14, 2022 | |
| Maps Block Apple Plugin | maps-block-apple-plugin-cve-2022-25858 | May 15, 2025 | Jul 15, 2022 | |
| Publisher Media Kit Plugin | publisher-media-kit-plugin-cve-2022-25858 | May 15, 2025 | Jul 15, 2022 | |
| Redhat_linux | — | no-fix-redhat-rpm-package | Jul 9, 2025 | Jul 15, 2022 |
| Retro Winamp Block Plugin | retro-winamp-block-plugin-cve-2022-25858 | May 15, 2025 | Jul 15, 2022 | |
| Simple Local Avatars Plugin | simple-local-avatars-plugin-cve-2022-25858 | May 15, 2025 | Jul 14, 2022 | |
| Simple Podcasting Plugin | simple-podcasting-plugin-cve-2022-25858 | May 15, 2025 | Jul 14, 2022 | |
| Sophi Plugin | sophi-plugin-cve-2022-25858 | May 15, 2025 | Jul 14, 2022 | |
| Splunk | splunk-upgrade-latest | Sep 30, 2025 | Jul 15, 2022 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub