An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the uri-template-lite npm package, when an attacker is able to supply arbitrary input to the "URI.expand" method
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| uri-template-lite(npm) | 0 | 22.9.0 | N/A |
CVSS Metrics