Skip to content

Commit 3f02214

Browse files
yetingliallansson
authored andcommitted
fix ReDoS-vulnerable regexp in addImage (parallax#3091)
1 parent 5ad9914 commit 3f02214

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

src/modules/addimage.js

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -630,7 +630,7 @@ import { atob, btoa } from "../libs/AtobBtoa.js";
630630
var result = null;
631631

632632
if (dataUrlParts.length === 2) {
633-
var extractedInfo = /^data:(\w*\/\w*);*(charset=[\w=-]*)*;*$/.exec(
633+
var extractedInfo = /^data:(\w*\/\w*);*(charset=(?!charset=)[\w=-]*)*;*$/.exec(
634634
dataUrlParts[0]
635635
);
636636
if (Array.isArray(extractedInfo)) {

0 commit comments

Comments
 (0)