CVE-2021-35065

Aliases:GHSA-cj88-88mr-972wBIT-gulp-2021-35065
Advisory lineage Upstream: 0 Downstream: 13
Modified
Published: 26 Dec 2022, 00:00
Last modified:14 Apr 2025, 18:31

Vulnerability Summary

Overall Risk (default)
medium
40/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
0.42% LOW
0% probability -0.03%
KEV
Not listed
Ransomware
No reports
Public exploits
2 found
Dark Web
Not detected

Timeline

26 Dec 2022, 00:00
Published
Vulnerability first disclosed
14 Apr 2025, 18:31
Last Modified
Vulnerability information updated

Description

The glob-parent package before 6.0.1 for Node.js allows ReDoS (regular expression denial of service) attacks against the enclosure regular expression.

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 0.42% Percentile: 62%

Techniques & Countermeasures

  • CWE-1333Inefficient Regular Expression Complexity

    The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

Affected Systems

  • gulpjsglob-parent

    ≥ 6.0.0, < 6.0.1

  • Npmglob-parent

    ≥ 6.0.0, < 6.0.1

References (11)