CVE-2022-2596Medium· 5.9▾ SunlitInefficient Regular Expression Complexity in GitHub repository node-fetch/node-fetch prior to 3.2.10.
▾ Sunlit zone — Low / medium · no exploitation signal
impact 32.5 · likelihood 0.3 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Stakeholder-Specific Vulnerability Categorization from CISA's ADP record at CVE.org: whether exploitation is observed, whether an attack can be automated, and how much of the system is at stake.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
1.3%
Inefficient Regular Expression Complexity in GitHub repository node-fetch/node-fetch prior to 3.2.10.
node-fetch >= 3.0.0, < 3.2.10Upgrade past the affected range:
node-fetch 3.2.10Connected by shared product, vendor, weakness, or advisory.
CVE-2022-0235Medium· 6.1node-fetch is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor
CVE-2024-21538High· 7.5Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization
CVE-2024-21490High· 7.5This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0
CVE-2026-102408Medium· 4.3Inefficient Regular Expression Complexity (CWE-1333) in Elasticsearch can lead to denial of service via Regular Expression Exponential Blowup (CAPEC-492)
CVE-2026-106454Medium· 4.3Twisted is an event-based framework for internet applications, supporting Python 3.6+
CVE-2026-106104High· 8.7Quasar Framework is a framework for building high-performance Vue.js user interfaces