Skip to content

Fixed regular expression denial of service

Compare
Choose a tag to compare
@taylorhakes taylorhakes released this 27 Dec 21:08
· 88 commits to master since this release

Possible denial of service was possible if unvalidated input is passed to fecha.parse. Input strings longer than 1000 characters now return false