Vulnerabilities > CVE-2023-26115 - Unspecified vulnerability in Word-Wrap Project Word-Wrap
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
NONE Integrity impact
NONE Availability impact
HIGH Summary
All versions of the package word-wrap are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of an insecure regular expression within the result variable.
Vulnerable Configurations
References
- https://github.com/jonschlinkert/word-wrap/blob/master/index.js%23L39
- https://github.com/jonschlinkert/word-wrap/blob/master/index.js%23L39
- https://github.com/jonschlinkert/word-wrap/releases/tag/1.2.4
- https://github.com/jonschlinkert/word-wrap/releases/tag/1.2.4
- https://security.netapp.com/advisory/ntap-20240621-0006/
- https://security.netapp.com/advisory/ntap-20240621-0006/
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-4058657
- https://security.snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-4058657
- https://security.snyk.io/vuln/SNYK-JS-WORDWRAP-3149973
- https://security.snyk.io/vuln/SNYK-JS-WORDWRAP-3149973