-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The GitHub Security Lab advisory explicitly identifies the 'rstart' regex as vulnerable through CodeQL analysis. The PoC demonstrates ReDoS via attribute patterns that trigger exponential backtracking in this regex. As a core HTML sanitization component processing untrusted input, this regex's inefficiency directly enables the vulnerability. The confidence is high due to explicit identification in the GHSL-2020-289 report and reproducible PoC.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| insane | npm | <= 2.6.2 |
KEV Misses 88% of Exploited CVEs- Get the report