Pull Requests Welcome: We need your help to fix some ReDoS vulnerabilities
Recently there were a large number of regular expression denial of service ( ReDoS ) vulnerabilities released to the public via GitHub issues. These issues don’t have patches but many of the maintainers are welcoming pull requests. I’m writing to ask the community for some help. If you have the time available or your company supports contributions to open source please consider helping fix these issues.
Below you will find a list of these currently public and unfixed vulnerabilities, sorted by npm monthly download count. While some of these issues may be unlikely to face actual exploitation given the typical use case of the affected libraries; code and its usage tends to change over time, so it can’t hurt to mitigate these issues before they have the chance to cause problems.
Here are a few other ReDoS issues that have been fixed recently to give you some inspiration for patches.
❤’s from the Node Security Team