CVE-2014-8882 — Uncontrolled Resource Consumption in Project Validator
Severity
—HIGH
No vectorEPSS
No EPSS data
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 31
Description
Regular Expression Denial of Service in validator
Versions of `validator` prior to 3.22.1 are affected by a regular expression denial of service vulnerability in the `isURL` method.
## Recommendation
Update to version 3.22.1 or later.