Elektrine lite

← Feed

@milo@types.pl

Post #879014

2026-02-23 15:59 UTC

one SEVERE security vulnerability found in your dependencies. a REGEX LIBRARY that you AREN'T USING is vulnerable to denial of service ATTACK if you feed it malicious user input which you AREN'T DOING

Replies (4)

  • @swift@merveilles.town 2026-02-23 16:44

    @milo if I had a dollar for every time I have been told my unit test framework can be DOS'd with malicious regex, I wouldn't be working in tech anymore.

    Open ##1951941

  • @dzamie@app.wafrn.net 2026-02-23 17:12

    I love stuff like this with personal code (scripts I make for my own use and nobody else's). Woah, this function breaks if I pass it a string not formatted like a date? Wow, I hope I never accidentally tell it that it's currently 06.BG.2026

    Open ##1951944

  • @EvelynDraken@zug.network 2026-02-23 22:43

    @milo hello maintainer, we here at company ltd love your library but we're very concerned about the severe security vulnerability in it, we'll have to stop using it what no ofc we're not going to pay you to fix a nonissue

    Open ##1951945

  • @thunderzizi@eggware.social 2026-02-24 16:52

    @milo if i may be "Gamer" this is what the project64 vulnerability incident was like. "this severely outdated version of project64 can run ARBITRARY CODE if you play a romhack that's malicious anyway. Never Use Any Version Again Ever" i know it's like Inaccurate or whatever but comeon

    Open ##1951946