All vulnerabilities

CVE-2023-26115

word-wrap vulnerable to Regular Expression Denial of Service

Description

All versions of the package word-wrap are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of an insecure regular expression within the result variable.

Patch Available

Fix available through Seal Security. 

No upgrade required, protect your application instantly.

Fix without upgrading
Score
Severity
Ecosystem
JavaScript
Publish Date
June 22, 2023
Modified Date
February 13, 2025
Score Vector
Affected Versions