yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2022-25883
Component Overview
Vulnerability Overview
Name
CVE-2022-25883
Source
NVD (
link
)
Debian (
link
)
Description
Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.
CWEs
CWE-1333
CWE-1333
CWE-1333
Published Date
Jun 21, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/npm/node-semver/blob/main/classes/range.js%23L97-L104
Broken Link
https://github.com/npm/node-semver/blob/main/internal/re.js%23L138
Broken Link
https://github.com/npm/node-semver/blob/main/internal/re.js%23L160
Broken Link
https://github.com/npm/node-semver/commit/717534ee353682f3bcf33e60a8af4292626d4441
Patch
https://github.com/npm/node-semver/pull/564
Patch
https://security.snyk.io/vuln/SNYK-JS-SEMVER-3247795
Exploit
https://github.com/npm/node-semver/blob/main/classes/range.js%23L97-L104
Broken Link
https://github.com/npm/node-semver/blob/main/internal/re.js%23L138
Broken Link
https://github.com/npm/node-semver/blob/main/internal/re.js%23L160
Broken Link
https://github.com/npm/node-semver/commit/717534ee353682f3bcf33e60a8af4292626d4441
Patch
https://github.com/npm/node-semver/pull/564
Patch
https://security.netapp.com/advisory/ntap-20241025-0004/
Third Party Advisory
https://security.snyk.io/vuln/SNYK-JS-SEMVER-3247795
Exploit
Analysis
#
Affected Component
Analysis
nodejs
Patched
Vulnerability Ratings
#
5.3
CVSSv31
7.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
nodejs-src
buildroot
2025.02.x
22.22.0
Not Affected
nodejs-src
buildroot
master
22.22.0
Not Affected
node
openwrt
master
22.23.0-r1
Not Affected
node
openwrt
openwrt-25.12
22.23.0-r1
Not Affected
nodejs
yocto
master
24.17.0
Not Affected
nodejs
yocto
scarthgap
20.20.2
Not Affected
Resolved with patches
#
nodejs (yocto:kirkstone)
#
Title
Author
Resolve
1
fix: better handling of whitespace (#564)
Luke Karrys <luke@lukekarrys.com>
CVE-2022-25883