Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

πŸ› [BUG]: path-to-regexp outputs backtracking regular expressions - https://github.com/advisories/GHSA-9wv6-86v2-598j No fix available #11384

Open
Samuel-Muriuki opened this issue Oct 31, 2024 · 0 comments

Comments

@Samuel-Muriuki
Copy link

Samuel-Muriuki commented Oct 31, 2024

πŸ› bug 描述

I am using antd@5.21.4 with react@18.3.1 and getting vulnerabilities notification.

πŸ“· 倍现ζ­₯ιͺ€ | Recurrence steps

$ npm audit
# npm audit report

path-to-regexp 2.0.0 - 3.2.0
Severity: high
path-to-regexp outputs backtracking regular expressions - GHSA-9wv6-86v2-598j
No fix available
node_modules/@refinedev/antd/node_modules/path-to-regexp
@ant-design/pro-layout <=4.3.2 || 4.7.3 - 7.20.0
Depends on vulnerable versions of path-to-regexp
node_modules/@refinedev/antd/node_modules/@ant-design/pro-layout
**@refinedev/antd ***
Depends on vulnerable versions of @ant-design/pro-layout
node_modules/@refinedev/antd

3 high severity vulnerabilities

Some issues need review, and may require choosing
a different dependency.

$ npm ls path-to-regexp
my-project
β”œβ”€β”¬ @refinedev/antd@5.43.1
β”‚ └─┬ @ant-design/pro-layout@7.17.12
β”‚ └── path-to-regexp@2.4.0
└─┬ @refinedev/cli@2.16.39
└─┬ @refinedev/devtools-server@1.1.37 invalid: "1.1.36" from node_modules/@refinedev/devtools
└─┬ express@4.21.1
└── path-to-regexp@0.1.10

$ npm ls send
my-project
└─┬ @refinedev/cli@2.16.39
└─┬ @refinedev/devtools-server@1.1.37 invalid: "1.1.36" from node_modules/@refinedev/devtools
└─┬ express@4.21.1
β”œβ”€β”€ send@0.19.0
└─┬ serve-static@1.16.2
└── send@0.19.0 deduped

🏞 ζœŸζœ›η»“ζžœ | Expected results

πŸ’» 倍现代码 | Recurrence code

Β© η‰ˆζœ¬δΏ‘ζ―

  • Ant Design Pro η‰ˆζœ¬: [e.g. 4.0.0]
  • umi η‰ˆζœ¬
  • ζ΅θ§ˆε™¨ηŽ―ε’ƒ
  • εΌ€ε‘ηŽ―ε’ƒ [e.g. mac OS]

πŸš‘ 兢他俑息

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant