You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The advisory for GHSA-fw3v-x4f2-v673 says that all versions of mistune before 2.0.3 are vulnerable. Given the fix was to modify a single regex, which isn't present in versions before 2.0.0a1, I think this claim is unlikely to be true. Is every version of mistune ever released (starting with 0.1.0) actually vulnerable to a ReDoS, or should there be a version bound of e.g. >1.8.4 on the advisory?
The text was updated successfully, but these errors were encountered:
The advisory for GHSA-fw3v-x4f2-v673 says that all versions of mistune before 2.0.3 are vulnerable. Given the fix was to modify a single regex, which isn't present in versions before 2.0.0a1, I think this claim is unlikely to be true. Is every version of mistune ever released (starting with 0.1.0) actually vulnerable to a ReDoS, or should there be a version bound of e.g. >1.8.4 on the advisory?
The text was updated successfully, but these errors were encountered: