segmentio/is-email

segmentio/is-email

Releases2
Frequency2 years 9 months
Last Release
Stars49
Component: loosely validate an email address.

CVE History

CVEPublishedCVSS v3CVSS v2
7.5 HIGH5 MEDIUM

A ReDoS (regular expression denial of service) flaw was found in the Segment is-email package before 1.0.1 for Node.js. An attacker that is able to provide crafted input to the isEmail(input) function may cause an application to consume an excessive amount of CPU.