Releases5
Frequency7 months 4 weeks
Last Release
A JavaScript TimeSpan library for node.js (and soon the browser)

CVE History

CVEAffectedPublishedCVSS v3CVSS v2
all versions, <= 2.3.07.5 HIGH5 MEDIUM

The timespan module is vulnerable to regular expression denial of service. Given 50k characters of untrusted user input it will block the event loop for around 10 seconds.