Description
The package forms before 1.2.1, from 1.3.0 and before 1.3.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via email validation.
Remediation
References
https://github.com/caolan/forms/pull/214
https://github.com/caolan/forms/pull/214/commits/d4bd5b5febfe49c1f585f162e04ec810f8dc47a0
https://snyk.io/vuln/SNYK-JS-FORMS-1296389
Related Vulnerabilities
CVE-2017-7656 Vulnerability in maven package org.eclipse.jetty:jetty-http
CVE-2019-10339 Vulnerability in maven package org.jenkins-ci.plugins:jx-resources
CVE-2013-6429 Vulnerability in maven package org.springframework:spring-web
CVE-2019-10295 Vulnerability in maven package org.jenkins-ci.plugins:crittercism-dsym
CVE-2020-15156 Vulnerability in npm package nodebb-plugin-blog-comments