Vulnerability Details CVE-2021-33502
The normalize-url package before 4.5.1, 5.x before 5.3.1, and 6.x before 6.0.1 for Node.js has a ReDoS (regular expression denial of service) issue because it has exponential performance for data: URLs.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 55.6%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2021-33502
-
cpe:2.3:a:normalize-url_project:normalize-url:4.3.0
-
cpe:2.3:a:normalize-url_project:normalize-url:4.4.0
-
cpe:2.3:a:normalize-url_project:normalize-url:4.4.1
-
cpe:2.3:a:normalize-url_project:normalize-url:4.5.0
-
cpe:2.3:a:normalize-url_project:normalize-url:5.0.0
-
cpe:2.3:a:normalize-url_project:normalize-url:5.1.0
-
cpe:2.3:a:normalize-url_project:normalize-url:5.2.0
-
cpe:2.3:a:normalize-url_project:normalize-url:5.2.1
-
cpe:2.3:a:normalize-url_project:normalize-url:5.3.0
-
cpe:2.3:a:normalize-url_project:normalize-url:6.0.0