regex
Activity
- Latest release
- 1mo ago
- Total releases
- 169
- Cadence
- ~26 days
- Last 12 months
- 7
Details
- License
- MIT OR Apache-2.0
- First release
- Dec 13, 2014
| Version | Released | |
|---|---|---|
1.13.1
unknown
|
1.13.1
unknown
Dependencies (9)
+ 1 more |
|
1.13.0
unknown
|
1.13.0
unknown
Dependencies (9)
+ 1 more |
|
1.12.4
unknown
|
1.12.4
unknown
Dependencies (9)
+ 1 more |
|
1.12.3
unknown
|
1.12.3
unknown
Dependencies (9)
+ 1 more |
|
1.12.2
unknown
|
1.12.2
unknown
Dependencies (9)
+ 1 more |
|
1.12.1
unknown
|
1.12.1
unknown
Dependencies (9)
+ 1 more |
|
1.12.0
unknown
yanked
|
1.12.0
unknown
yanked
Dependencies (9)
+ 1 more |
|
1.11.3
unknown
|
1.11.3
unknown
Dependencies (9)
+ 1 more |
|
1.11.2
unknown
|
1.11.2
unknown
Dependencies (9)
+ 1 more |
|
1.11.1
unknown
|
1.11.1
unknown
Dependencies (10)
+ 2 more |
|
1.11.0
unknown
|
1.11.0
unknown
Dependencies (10)
+ 2 more |
|
1.10.6
unknown
|
1.10.6
unknown
Dependencies (10)
+ 2 more |
|
1.10.5
unknown
|
1.10.5
unknown
Dependencies (10)
+ 2 more |
|
1.10.4
unknown
|
1.10.4
unknown
Dependencies (10)
+ 2 more |
|
1.10.3
unknown
|
1.10.3
unknown
Dependencies (10)
+ 2 more |
|
1.10.2
unknown
|
1.10.2
unknown
Dependencies (10)
+ 2 more |
|
1.10.1
unknown
|
1.10.1
unknown
Dependencies (10)
+ 2 more |
|
1.10.0
unknown
|
1.10.0
unknown
Dependencies (10)
+ 2 more |
|
1.9.6
unknown
|
1.9.6
unknown
Dependencies (10)
+ 2 more |
|
1.9.5
unknown
|
1.9.5
unknown
Dependencies (10)
+ 2 more |
|
1.9.4
unknown
|
1.9.4
unknown
Dependencies (10)
+ 2 more |
|
1.9.3
unknown
|
1.9.3
unknown
Dependencies (10)
+ 2 more |
|
1.9.2
unknown
|
1.9.2
unknown
Dependencies (10)
+ 2 more |
|
1.9.1
unknown
|
1.9.1
unknown
Dependencies (10)
+ 2 more |
|
1.9.0
unknown
|
1.9.0
unknown
Dependencies (10)
+ 2 more |
|
1.8.4
unknown
|
1.8.4
unknown
Dependencies (6)
|
|
1.8.3
unknown
|
1.8.3
unknown
Dependencies (6)
|
|
1.8.2
unknown
|
1.8.2
unknown
Dependencies (6)
|
|
1.8.1
unknown
|
1.8.1
unknown
Dependencies (6)
|
|
1.8.0
unknown
|
1.8.0
unknown
Dependencies (6)
|
|
1.7.3
unknown
|
1.7.3
unknown
Dependencies (6)
|
|
1.7.2
unknown
|
1.7.2
unknown
Dependencies (6)
|
|
1.7.1
unknown
|
1.7.1
unknown
Dependencies (6)
|
|
1.7.0
unknown
|
1.7.0
unknown
Dependencies (6)
|
|
1.6.0
unknown
|
1.6.0
unknown
Dependencies (6)
|
|
1.5.6
unknown
|
1.5.6
unknown
Dependencies (6)
|
|
1.5.5
unknown
|
1.5.5
unknown
Dependencies (6)
|
|
1.5.4
unknown
1 CVE
CVE-2022-24713
GHSA-m5pq-gvj9-9vr8
RUSTSEC-2022-0013
Mar 08, 2022
Rust's regex crate vulnerable to regular expression denial of service
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The Rust Security Response WG was notified that the This issue has been assigned CVE-2022-24713. The severity of this vulnerability is "high" when the OverviewThe Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. Affected versionsAll versions of the MitigationsWe recommend everyone accepting user-controlled regexes to upgrade immediately to the latest version of the Unfortunately there is no fixed set of problematic regexes, as there are practically infinite regexes that could be crafted to exploit this vulnerability. Because of this, we do not recommend denying known problematic regexes. AcknowledgementsWe want to thank Addison Crump for responsibly disclosing this to us according to the Rust security policy, and for helping review the fix. We also want to thank Andrew Gallant for developing the fix, and Pietro Albini for coordinating the disclosure and writing this advisory. Fixed in
1.5.5
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.5.4
unknown
Dependencies (6)
|
|
1.5.3
unknown
1 CVE
CVE-2022-24713
GHSA-m5pq-gvj9-9vr8
RUSTSEC-2022-0013
Mar 08, 2022
Rust's regex crate vulnerable to regular expression denial of service
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The Rust Security Response WG was notified that the This issue has been assigned CVE-2022-24713. The severity of this vulnerability is "high" when the OverviewThe Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. Affected versionsAll versions of the MitigationsWe recommend everyone accepting user-controlled regexes to upgrade immediately to the latest version of the Unfortunately there is no fixed set of problematic regexes, as there are practically infinite regexes that could be crafted to exploit this vulnerability. Because of this, we do not recommend denying known problematic regexes. AcknowledgementsWe want to thank Addison Crump for responsibly disclosing this to us according to the Rust security policy, and for helping review the fix. We also want to thank Andrew Gallant for developing the fix, and Pietro Albini for coordinating the disclosure and writing this advisory. Fixed in
1.5.5
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.5.3
unknown
Dependencies (6)
|
|
1.5.2
unknown
1 CVE
CVE-2022-24713
GHSA-m5pq-gvj9-9vr8
RUSTSEC-2022-0013
Mar 08, 2022
Rust's regex crate vulnerable to regular expression denial of service
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The Rust Security Response WG was notified that the This issue has been assigned CVE-2022-24713. The severity of this vulnerability is "high" when the OverviewThe Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. Affected versionsAll versions of the MitigationsWe recommend everyone accepting user-controlled regexes to upgrade immediately to the latest version of the Unfortunately there is no fixed set of problematic regexes, as there are practically infinite regexes that could be crafted to exploit this vulnerability. Because of this, we do not recommend denying known problematic regexes. AcknowledgementsWe want to thank Addison Crump for responsibly disclosing this to us according to the Rust security policy, and for helping review the fix. We also want to thank Andrew Gallant for developing the fix, and Pietro Albini for coordinating the disclosure and writing this advisory. Fixed in
1.5.5
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.5.2
unknown
Dependencies (6)
|
|
1.5.1
unknown
1 CVE
CVE-2022-24713
GHSA-m5pq-gvj9-9vr8
RUSTSEC-2022-0013
Mar 08, 2022
Rust's regex crate vulnerable to regular expression denial of service
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The Rust Security Response WG was notified that the This issue has been assigned CVE-2022-24713. The severity of this vulnerability is "high" when the OverviewThe Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. Affected versionsAll versions of the MitigationsWe recommend everyone accepting user-controlled regexes to upgrade immediately to the latest version of the Unfortunately there is no fixed set of problematic regexes, as there are practically infinite regexes that could be crafted to exploit this vulnerability. Because of this, we do not recommend denying known problematic regexes. AcknowledgementsWe want to thank Addison Crump for responsibly disclosing this to us according to the Rust security policy, and for helping review the fix. We also want to thank Andrew Gallant for developing the fix, and Pietro Albini for coordinating the disclosure and writing this advisory. Fixed in
1.5.5
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.5.1
unknown
Dependencies (6)
|
|
1.5.0
unknown
1 CVE
CVE-2022-24713
GHSA-m5pq-gvj9-9vr8
RUSTSEC-2022-0013
Mar 08, 2022
Rust's regex crate vulnerable to regular expression denial of service
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The Rust Security Response WG was notified that the This issue has been assigned CVE-2022-24713. The severity of this vulnerability is "high" when the OverviewThe Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. Affected versionsAll versions of the MitigationsWe recommend everyone accepting user-controlled regexes to upgrade immediately to the latest version of the Unfortunately there is no fixed set of problematic regexes, as there are practically infinite regexes that could be crafted to exploit this vulnerability. Because of this, we do not recommend denying known problematic regexes. AcknowledgementsWe want to thank Addison Crump for responsibly disclosing this to us according to the Rust security policy, and for helping review the fix. We also want to thank Andrew Gallant for developing the fix, and Pietro Albini for coordinating the disclosure and writing this advisory. Fixed in
1.5.5
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.5.0
unknown
Dependencies (6)
|
|
1.4.6
unknown
1 CVE
CVE-2022-24713
GHSA-m5pq-gvj9-9vr8
RUSTSEC-2022-0013
Mar 08, 2022
Rust's regex crate vulnerable to regular expression denial of service
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The Rust Security Response WG was notified that the This issue has been assigned CVE-2022-24713. The severity of this vulnerability is "high" when the OverviewThe Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. Affected versionsAll versions of the MitigationsWe recommend everyone accepting user-controlled regexes to upgrade immediately to the latest version of the Unfortunately there is no fixed set of problematic regexes, as there are practically infinite regexes that could be crafted to exploit this vulnerability. Because of this, we do not recommend denying known problematic regexes. AcknowledgementsWe want to thank Addison Crump for responsibly disclosing this to us according to the Rust security policy, and for helping review the fix. We also want to thank Andrew Gallant for developing the fix, and Pietro Albini for coordinating the disclosure and writing this advisory. Fixed in
1.5.5
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.4.6
unknown
Dependencies (6)
|
|
1.4.5
unknown
1 CVE
CVE-2022-24713
GHSA-m5pq-gvj9-9vr8
RUSTSEC-2022-0013
Mar 08, 2022
Rust's regex crate vulnerable to regular expression denial of service
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The Rust Security Response WG was notified that the This issue has been assigned CVE-2022-24713. The severity of this vulnerability is "high" when the OverviewThe Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. Affected versionsAll versions of the MitigationsWe recommend everyone accepting user-controlled regexes to upgrade immediately to the latest version of the Unfortunately there is no fixed set of problematic regexes, as there are practically infinite regexes that could be crafted to exploit this vulnerability. Because of this, we do not recommend denying known problematic regexes. AcknowledgementsWe want to thank Addison Crump for responsibly disclosing this to us according to the Rust security policy, and for helping review the fix. We also want to thank Andrew Gallant for developing the fix, and Pietro Albini for coordinating the disclosure and writing this advisory. Fixed in
1.5.5
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.4.5
unknown
Dependencies (6)
|
|
1.4.4
unknown
1 CVE
CVE-2022-24713
GHSA-m5pq-gvj9-9vr8
RUSTSEC-2022-0013
Mar 08, 2022
Rust's regex crate vulnerable to regular expression denial of service
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The Rust Security Response WG was notified that the This issue has been assigned CVE-2022-24713. The severity of this vulnerability is "high" when the OverviewThe Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. Affected versionsAll versions of the MitigationsWe recommend everyone accepting user-controlled regexes to upgrade immediately to the latest version of the Unfortunately there is no fixed set of problematic regexes, as there are practically infinite regexes that could be crafted to exploit this vulnerability. Because of this, we do not recommend denying known problematic regexes. AcknowledgementsWe want to thank Addison Crump for responsibly disclosing this to us according to the Rust security policy, and for helping review the fix. We also want to thank Andrew Gallant for developing the fix, and Pietro Albini for coordinating the disclosure and writing this advisory. Fixed in
1.5.5
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.4.4
unknown
Dependencies (6)
|
|
1.4.3
unknown
1 CVE
CVE-2022-24713
GHSA-m5pq-gvj9-9vr8
RUSTSEC-2022-0013
Mar 08, 2022
Rust's regex crate vulnerable to regular expression denial of service
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The Rust Security Response WG was notified that the This issue has been assigned CVE-2022-24713. The severity of this vulnerability is "high" when the OverviewThe Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. Affected versionsAll versions of the MitigationsWe recommend everyone accepting user-controlled regexes to upgrade immediately to the latest version of the Unfortunately there is no fixed set of problematic regexes, as there are practically infinite regexes that could be crafted to exploit this vulnerability. Because of this, we do not recommend denying known problematic regexes. AcknowledgementsWe want to thank Addison Crump for responsibly disclosing this to us according to the Rust security policy, and for helping review the fix. We also want to thank Andrew Gallant for developing the fix, and Pietro Albini for coordinating the disclosure and writing this advisory. Fixed in
1.5.5
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.4.3
unknown
Dependencies (7)
|
|
1.4.2
unknown
1 CVE
CVE-2022-24713
GHSA-m5pq-gvj9-9vr8
RUSTSEC-2022-0013
Mar 08, 2022
Rust's regex crate vulnerable to regular expression denial of service
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The Rust Security Response WG was notified that the This issue has been assigned CVE-2022-24713. The severity of this vulnerability is "high" when the OverviewThe Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. Affected versionsAll versions of the MitigationsWe recommend everyone accepting user-controlled regexes to upgrade immediately to the latest version of the Unfortunately there is no fixed set of problematic regexes, as there are practically infinite regexes that could be crafted to exploit this vulnerability. Because of this, we do not recommend denying known problematic regexes. AcknowledgementsWe want to thank Addison Crump for responsibly disclosing this to us according to the Rust security policy, and for helping review the fix. We also want to thank Andrew Gallant for developing the fix, and Pietro Albini for coordinating the disclosure and writing this advisory. Fixed in
1.5.5
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.4.2
unknown
Dependencies (7)
|
|
1.4.1
unknown
1 CVE
CVE-2022-24713
GHSA-m5pq-gvj9-9vr8
RUSTSEC-2022-0013
Mar 08, 2022
Rust's regex crate vulnerable to regular expression denial of service
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The Rust Security Response WG was notified that the This issue has been assigned CVE-2022-24713. The severity of this vulnerability is "high" when the OverviewThe Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. Affected versionsAll versions of the MitigationsWe recommend everyone accepting user-controlled regexes to upgrade immediately to the latest version of the Unfortunately there is no fixed set of problematic regexes, as there are practically infinite regexes that could be crafted to exploit this vulnerability. Because of this, we do not recommend denying known problematic regexes. AcknowledgementsWe want to thank Addison Crump for responsibly disclosing this to us according to the Rust security policy, and for helping review the fix. We also want to thank Andrew Gallant for developing the fix, and Pietro Albini for coordinating the disclosure and writing this advisory. Fixed in
1.5.5
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.4.1
unknown
Dependencies (7)
|
|
1.4.0
unknown
1 CVE
CVE-2022-24713
GHSA-m5pq-gvj9-9vr8
RUSTSEC-2022-0013
Mar 08, 2022
Rust's regex crate vulnerable to regular expression denial of service
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The Rust Security Response WG was notified that the This issue has been assigned CVE-2022-24713. The severity of this vulnerability is "high" when the OverviewThe Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. Affected versionsAll versions of the MitigationsWe recommend everyone accepting user-controlled regexes to upgrade immediately to the latest version of the Unfortunately there is no fixed set of problematic regexes, as there are practically infinite regexes that could be crafted to exploit this vulnerability. Because of this, we do not recommend denying known problematic regexes. AcknowledgementsWe want to thank Addison Crump for responsibly disclosing this to us according to the Rust security policy, and for helping review the fix. We also want to thank Andrew Gallant for developing the fix, and Pietro Albini for coordinating the disclosure and writing this advisory. Fixed in
1.5.5
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.4.0
unknown
Dependencies (7)
|
|
1.3.9
unknown
1 CVE
CVE-2022-24713
GHSA-m5pq-gvj9-9vr8
RUSTSEC-2022-0013
Mar 08, 2022
Rust's regex crate vulnerable to regular expression denial of service
7.5
/ 10
High
Network
Low
None
None
Unchanged
None
None
High
The Rust Security Response WG was notified that the This issue has been assigned CVE-2022-24713. The severity of this vulnerability is "high" when the OverviewThe Unfortunately a bug was discovered in the mitigations designed to prevent untrusted regexes to take an arbitrary amount of time during parsing, and it's possible to craft regexes that bypass such mitigations. This makes it possible to perform denial of service attacks by sending specially crafted regexes to services accepting user-controlled, untrusted regexes. Affected versionsAll versions of the MitigationsWe recommend everyone accepting user-controlled regexes to upgrade immediately to the latest version of the Unfortunately there is no fixed set of problematic regexes, as there are practically infinite regexes that could be crafted to exploit this vulnerability. Because of this, we do not recommend denying known problematic regexes. AcknowledgementsWe want to thank Addison Crump for responsibly disclosing this to us according to the Rust security policy, and for helping review the fix. We also want to thank Andrew Gallant for developing the fix, and Pietro Albini for coordinating the disclosure and writing this advisory. Fixed in
1.5.5
References
Updated Nov 08, 2023 · Source: OSV.dev |
1.3.9
unknown
Dependencies (7)
|