Terser is a JavaScript minification library embedded in build pipelines and web-optimization tooling, where its compact product line belies its presence across downstream projects. The durable vulnerability signal centers on inefficient regular expression complexity in its HTML minification and code transformation components. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Terser over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-37620HIGH A Regular Expression Denial of Service (ReDoS) flaw was found in kangax html-minifier 4.0.0 because of the reCustomIgnore regular expression. | Oct 31, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-25858HIGH The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions. | Jul 15, 2022 | 7.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Terser.
Media articles that mention a CVE ID that affects a product developed by Terser — matched by CVE ID, not by vendor name.