{"id":"GHSA-h6ch-v84p-w6p9","summary":"Regular Expression Denial of Service (ReDoS)","details":"A vulnerability was found in diff before v3.5.0, the affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) attacks.","modified":"2026-07-17T21:09:07.754038891Z","published":"2019-06-13T18:58:54Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2019-06-13T18:54:38Z","nvd_published_at":null,"cwe_ids":["CWE-400"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/kpdecker/jsdiff/commit/2aec4298639bf30fb88a00b356bf404d3551b8c0"},{"type":"WEB","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1552148"},{"type":"WEB","url":"https://snyk.io/vuln/npm:diff:20180305"},{"type":"WEB","url":"https://www.npmjs.com/advisories/1631"},{"type":"WEB","url":"https://www.whitesourcesoftware.com/vulnerability-database/WS-2018-0590"}],"affected":[{"package":{"name":"diff","ecosystem":"npm","purl":"pkg:npm/diff"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"3.5.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2019/06/GHSA-h6ch-v84p-w6p9/GHSA-h6ch-v84p-w6p9.json"}}],"schema_version":"1.9.0"}