{"schema_version":"1.7.5","id":"CVE-2021-3807","published":"2021-09-17T07:15:09.273Z","modified":"2026-08-07T15:12:00.369792984Z","aliases":["GHSA-93q8-gq69-wqmw"],"related":["ALSA-2021:5171","ALSA-2022:0350","ALSA-2022:6595","CGA-7v44-hxgv-54c8","SUSE-RU-2024:0511-1","SUSE-SU-2022:0531-1","SUSE-SU-2022:0563-1","SUSE-SU-2022:0569-1","SUSE-SU-2022:0570-1","SUSE-SU-2022:0657-1","SUSE-SU-2022:0704-1","SUSE-SU-2022:0715-1","SUSE-SU-2022:1717-1","SUSE-SU-2023:2575-1","SUSE-SU-2023:2578-1","SUSE-SU-2023:2579-1","SUSE-SU-2024:0191-1","SUSE-SU-2024:0196-1","SUSE-SU-2024:0486-1","SUSE-SU-2024:0487-1","openSUSE-SU-2022:0657-1","openSUSE-SU-2022:0704-1","openSUSE-SU-2022:0715-1","openSUSE-SU-2024:12723-1"],"details":"ansi-regex is vulnerable to Inefficient Regular Expression Complexity","affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/chalk/ansi-regex","events":[{"introduced":"a1d92466388fc8766b63bfab27ddc1e1df897dda"},{"fixed":"64735d25eb839b55bc9fae3877edb702b4c92ca2"},{"introduced":"0a8cc19946c03c38520fe8c086b8adb66f9cce0b"},{"last_affected":"c1b5e45f7c65a332ffb03ac8e5804ad37c579cdc"},{"fixed":"8d1d7cdb586269882c4bdc1b7325d0c58c8f76f9"}],"database_specific":{"cpe":["cpe:2.3:a:ansi-regex_project:ansi-regex:*:*:*:*:*:node.js:*:*","cpe:2.3:a:ansi-regex_project:ansi-regex:3.0.0:*:*:*:*:node.js:*:*","cpe:2.3:a:ansi-regex_project:ansi-regex:5.0.0:*:*:*:*:node.js:*:*","cpe:2.3:a:ansi-regex_project:ansi-regex:6.0.0:*:*:*:*:node.js:*:*"],"extracted_events":[{"introduced":"4.0.0"},{"fixed":"4.1.1"},{"introduced":"3.0.0"},{"last_affected":"3.0.0"},{"introduced":"5.0.0"},{"last_affected":"5.0.0"},{"introduced":"6.0.0"},{"last_affected":"6.0.0"}],"source":["CPE_RANGE","CPE_STRING","REFERENCES"]}}],"versions":["3.0.0","5.0.0","6.0.0","v4.1.0","v6.0.0","v5.0.0","v4.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-3807.json"}}],"references":[{"type":"ADVISORY","url":"https://security.netapp.com/advisory/ntap-20221014-0002/"},{"type":"FIX","url":"https://github.com/chalk/ansi-regex/commit/8d1d7cdb586269882c4bdc1b7325d0c58c8f76f9"},{"type":"FIX","url":"https://huntr.dev/bounties/5b3cf33b-ede0-4398-9974-800876dfd994"},{"type":"FIX","url":"https://www.oracle.com/security-alerts/cpuapr2022.html"}],"database_specific":{"unresolved_ranges":[{"cpes":["cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.15.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"1.15.0"},{"last_affected":"1.15.0"}],"source":"CPE_STRING","vendor_product":"oracle:communications_cloud_native_core_policy"}]},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}