-
-
Notifications
You must be signed in to change notification settings - Fork 1.2k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Security vulnerability in zod@3.22.2 #2828
Comments
This is -- there is no other way to say it -- just another snyk bullshit report. It's not even involving any code from this package. Pure bullshit. |
@matjaeck Explain? Looking at the report and the included video shows that it does take significantly longer to process - I'll verify if this is the case tomorrow |
probably a duplicate of #2787 |
I decided to make some tests in StackBlitz - and in my testing, only 3.22.0+ are vulnerable. |
Fixed by #2824 Landed in Zod v3.22.3 |
Hi maintainers,
I am reporting a security vulnerability in zod.
Vulnerability type: Regular Expression Denial of Service (ReDoS) [High Severity]
Additional information: https://security.snyk.io/vuln/SNYK-JS-ZOD-5925617
Best regards,
Arie
The text was updated successfully, but these errors were encountered: