Segment maintains a focused set of data validation libraries, primarily email and URL validators, that are integrated into applications across many development stacks. The recurring vulnerability signal centers on computational-complexity weaknesses in input validation, particularly inefficient regular expression patterns and uncontrolled resource consumption that can arise from pathological inputs. Live severity, exploitation, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Segment over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2018-25079HIGH A vulnerability was found in Segmentio is-url up to 1.2.2. It has been rated as problematic. Affected by this issue is some unknown functionality of the file index.js. The manipula | Feb 4, 2023 | 7.5 | 25 | NO | NO |
CVE-2021-36716HIGH A ReDoS (regular expression denial of service) flaw was found in the Segment is-email package before 1.0.1 for Node.js. An attacker that is able to provide crafted input to the isE | Jul 14, 2021 | 7.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Segment.
Media articles that mention a CVE ID that affects a product developed by Segment — matched by CVE ID, not by vendor name.