The Semver Regex Project maintains a narrowly scoped regular-expression utility for semantic versioning validation, which despite its small direct footprint may be embedded in development tools and package managers where parsing dependencies is routine. The observed vulnerability profile reflects the parsing-oriented context of the product, though the vendor's disclosures remain minimal in volume. Current exploitation activity, severity breakdown, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Semver Regex Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3795HIGH semver-regex is vulnerable to Inefficient Regular Expression Complexity | Sep 15, 2021 | 7.5 | 25 | NO | NO |
CVE-2021-43307HIGH An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input to the test() metho | Jun 2, 2022 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Semver Regex Project.
Media articles that mention a CVE ID that affects a product developed by Semver Regex Project — matched by CVE ID, not by vendor name.