CVE Vulnerabilities

CVE-2022-25858

Inefficient Regular Expression Complexity

Published: Jul 15, 2022 | Modified: Jun 17, 2026
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions.

Weakness

The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

Affected Software

NameVendorStart VersionEnd Version
TerserTerser*4.8.1 (excluding)
TerserTerser5.0.0 (including)5.14.2 (excluding)
Red Hat OpenShift Service Mesh 2.2 for RHEL 8RedHatopenshift-service-mesh/prometheus-rhel8:2.2.7-7*
RHINT Service Registry 2.3.0 GARedHatterser*
Chromium-browserUbuntutrusty*
Chromium-browserUbuntuupstream*
Chromium-browserUbuntuxenial*
Node-terserUbuntufocal*
Node-terserUbuntuimpish*
Node-terserUbuntukinetic*
Node-terserUbuntulunar*
Node-terserUbuntumantic*
Node-terserUbuntuoracular*
Node-terserUbuntuplucky*
Node-terserUbuntuquesting*
Qt6-webengineUbuntukinetic*
Qt6-webengineUbuntulunar*
Qt6-webengineUbuntumantic*
Qt6-webengineUbuntuoracular*
Qt6-webengineUbuntuplucky*
Qt6-webengineUbuntuquesting*

Potential Mitigations

References