Snyk issue : Regular Expression Denial of Service #638

Closed
opened 2025-12-29 08:31:40 +01:00 by adam · 3 comments
Owner

Originally created by @maneesh-darisi-eb on GitHub (Oct 9, 2024).

Describe the bug

Detailed paths
Introduced through: project@* › WireMock.Net@1.6.6 › Handlebars.Net.Helpers.Xslt@2.4.4 › System.Xml.XmlDocument@4.3.0 › System.Xml.ReaderWriter@4.3.0 › System.Text.RegularExpressions@4.3.0
Fix: No remediation path available.
Security information
Factors contributing to the scoring:
Snyk: CVSS v3.1 7.5 - High Severity
NVD: CVSS v3.1 7.5 - High Severity

Expected behavior:

A clear and concise description of what you expected to happen.

WireMock.Net@1.6.6 needs to update the System.Text.RegularExpressions@4.3.0 to 4.3.1

Originally created by @maneesh-darisi-eb on GitHub (Oct 9, 2024). ### Describe the bug Detailed paths Introduced through: project@* › WireMock.Net@1.6.6 › Handlebars.Net.Helpers.Xslt@2.4.4 › System.Xml.XmlDocument@4.3.0 › System.Xml.ReaderWriter@4.3.0 › System.Text.RegularExpressions@4.3.0 Fix: No remediation path available. Security information Factors contributing to the scoring: Snyk: [CVSS v3.1 7.5](https://security.snyk.io/vuln/SNYK-DOTNET-SYSTEMTEXTREGULAREXPRESSIONS-174708) - High Severity NVD: [CVSS v3.1 7.5](https://nvd.nist.gov/vuln/detail/CVE-2019-0820) - High Severity ### Expected behavior: A clear and concise description of what you expected to happen. WireMock.Net@1.6.6 needs to update the System.Text.RegularExpressions@4.3.0 to 4.3.1
adam added the bug label 2025-12-29 08:31:40 +01:00
adam closed this issue 2025-12-29 08:31:40 +01:00
Author
Owner
@StefH commented on GitHub (Oct 9, 2024): https://github.com/StefH/RandomDataGenerator/pull/27 https://github.com/Handlebars-Net/Handlebars.Net.Helpers/pull/101
Author
Owner

@StefH commented on GitHub (Oct 9, 2024):

https://github.com/WireMock-Net/WireMock.Net/pull/1194

@StefH commented on GitHub (Oct 9, 2024): https://github.com/WireMock-Net/WireMock.Net/pull/1194
Author
Owner

@maneesh-darisi-eb commented on GitHub (Oct 10, 2024):

@StefH Thanks for the quick fix . Could please let me know by when will this be released ?

@maneesh-darisi-eb commented on GitHub (Oct 10, 2024): @StefH Thanks for the quick fix . Could please let me know by when will this be released ?
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: starred/WireMock.Net#638