Url Regex Project maintains a narrowly scoped regular-expression utility focused on URL parsing and validation, which despite limited product breadth sits as a common dependency in web applications and HTTP tooling across the landscape. The observed vulnerabilities center on the core url_regex product and reflect the parsing complexity inherent to regex-based URL matching. Current exploitation activity, severity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Url Regex Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-21195HIGH All versions of package url-regex are vulnerable to Regular Expression Denial of Service (ReDoS) which can cause the CPU usage to crash. | May 20, 2022 | 7.5 | 24 | NO | NO |
CVE-2020-7661HIGH all versions of url-regex are vulnerable to Regular Expression Denial of Service. An attacker providing a very long string in String.test can cause a Denial of Service. | Jun 4, 2020 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Url Regex Project.
Media articles that mention a CVE ID that affects a product developed by Url Regex Project — matched by CVE ID, not by vendor name.