Skip to main content

Vendor archive

is-svg_project CVEs

Beta · best-effort

2 CVEs tagged to vendor is-svg_project0 Critical, 2 High, 0 Medium, 0 Low, 0 Unrated.

CVE-2021-29059

Published Jun 21, 2021

A vulnerability was discovered in IS-SVG version 2.1.0 to 4.2.2 and below where a Regular Expression Denial of Service (ReDOS) occurs if the application is provided and checks a c…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-28092

Published Mar 12, 2021

The is-svg package 2.1.0 through 4.2.1 for Node.js uses a regular expression that is vulnerable to Regular Expression Denial of Service (ReDoS). If an attacker provides a maliciou…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-2 of 2 CVEsPage 1 of 1