CVE-2022-31147
HIGHjQuery Validation Plugin <1.19.5 - DoS
Title source: llmDescription
The jQuery Validation Plugin (jquery-validation) provides drop-in validation for forms. Versions of jquery-validation prior to 1.19.5 are vulnerable to regular expression denial of service (ReDoS) when an attacker is able to supply arbitrary input to the url2 method. This is due to an incomplete fix for CVE-2021-43306. Users should upgrade to version 1.19.5 to receive a patch.
Exploits (1)
References (3)
Scores
CVSS v3
7.5
EPSS
0.0032
EPSS Percentile
55.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-1333
Status
published
Products (2)
jqueryvalidation/jquery_validation
< 1.19.5
npm/jquery-validation
0 - 1.19.5npm
Published
Jul 14, 2022
Tracked Since
Feb 18, 2026