{"schema_version":"1.9.0","id":"GHSA-px4h-xg32-q955","published":"2021-06-08T23:11:43Z","modified":"2023-11-08T04:06:04.745015Z","aliases":["CVE-2021-33502"],"summary":"ReDoS in normalize-url","details":"The normalize-url package before 4.5.1, 5.x before 5.3.1, and 6.x before 6.0.1 for Node.js has a ReDoS (regular expression denial of service) issue because it has exponential performance for data: URLs.","affected":[{"package":{"name":"normalize-url","ecosystem":"npm","purl":"pkg:npm/normalize-url"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.3.0"},{"fixed":"4.5.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/06/GHSA-px4h-xg32-q955/GHSA-px4h-xg32-q955.json"}},{"package":{"name":"normalize-url","ecosystem":"npm","purl":"pkg:npm/normalize-url"},"ranges":[{"type":"SEMVER","events":[{"introduced":"5.0.0"},{"fixed":"5.3.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/06/GHSA-px4h-xg32-q955/GHSA-px4h-xg32-q955.json"}},{"package":{"name":"normalize-url","ecosystem":"npm","purl":"pkg:npm/normalize-url"},"ranges":[{"type":"SEMVER","events":[{"introduced":"6.0.0"},{"fixed":"6.0.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/06/GHSA-px4h-xg32-q955/GHSA-px4h-xg32-q955.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-33502"},{"type":"WEB","url":"https://github.com/sindresorhus/normalize-url/commit/b1fdb5120b6d27a88400d8800e67ff5a22bd2103"},{"type":"PACKAGE","url":"https://github.com/sindresorhus/normalize-url"},{"type":"WEB","url":"https://github.com/sindresorhus/normalize-url/releases/tag/v6.0.1"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20210706-0001"}],"database_specific":{"cwe_ids":["CWE-400"],"github_reviewed":true,"github_reviewed_at":"2021-05-28T17:56:25Z","nvd_published_at":"2021-05-24T16:15:00Z","severity":"HIGH"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}