HIGH
GHSA-36jr-mh4h-2g58
d3-color vulnerable to ReDoS
Summary
The d3-color module provides representations for various color spaces in the browser. Versions prior to 3.1.0 are vulnerable to a Regular expression Denial of Service. This issue has been patched in version 3.1.0. There are no known workarounds.
Affected packages
| Ecosystem | Package | Affected versions | Fixed versions |
|---|---|---|---|
| npm | d3-color | — | 3.1.0 |
Remediation: Upgrade to 3.1.0 or later.
References
Includes data from the GitHub Advisory Database, licensed under CC-BY 4.0.