Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.
{ "binaries": [ { "binary_name": "libjs-semver", "binary_version": "2.1.0-2ubuntu0.0.1~esm1" }, { "binary_name": "node-semver", "binary_version": "2.1.0-2ubuntu0.0.1~esm1" } ] }
{ "binaries": [ { "binary_name": "libjs-semver", "binary_version": "2.1.0-2ubuntu0.1~esm1" }, { "binary_name": "node-semver", "binary_version": "2.1.0-2ubuntu0.1~esm1" } ] }
{ "binaries": [ { "binary_name": "node-semver", "binary_version": "5.4.1-1" } ] }
{ "binaries": [ { "binary_name": "node-semver", "binary_version": "7.1.3-1" } ] }
{ "binaries": [ { "binary_name": "node-semver", "binary_version": "7.3.5+~7.3.8-1" } ] }
{ "binaries": [ { "binary_name": "node-semver", "binary_version": "7.5.4+~7.5.0-2" } ] }
{ "binaries": [ { "binary_name": "node-semver", "binary_version": "7.6.1+~7.5.8-2" } ] }