CVE-2022-25887

MEDIUM

Apostrophecms Sanitize-html < 2.7.1 - Denial of Service

Title source: rule
STIX 2.1

Description

The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal.

Scores

CVSS v3 5.3
EPSS 0.0045
EPSS Percentile 63.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L

Details

CWE
CWE-1333
Status published
Products (2)
apostrophecms/sanitize-html < 2.7.1
npm/sanitize-html 0 - 2.7.1npm
Published Aug 30, 2022
Tracked Since Feb 18, 2026