CVE-2025-45143

string-math v1.2.2 was discovered to contain a Regex Denial of Service (ReDoS) which is exploited via a crafted input.
Configurations

Configuration 1 (hide)

cpe:2.3:a:devrafalko:string-math:1.2.2:*:*:*:*:node.js:*:*

History

18 Oct 2025, 01:41

Type Values Removed Values Added
First Time Devrafalko
Devrafalko string-math
CPE cpe:2.3:a:devrafalko:string-math:1.2.2:*:*:*:*:node.js:*:*
Summary
  • (es) Se descubrió que string-math v1.2.2 contiene una denegación de servicio de expresiones regulares (ReDoS) que se explota a través de una entrada manipulada.
References () https://gist.github.com/6en6ar/361608bccedb808061359481fe2f1b39 - () https://gist.github.com/6en6ar/361608bccedb808061359481fe2f1b39 - Exploit, Third Party Advisory
References () https://github.com/devrafalko/string-math/blob/master/string-math.js - () https://github.com/devrafalko/string-math/blob/master/string-math.js - Product
References () https://www.npmjs.com/package/string-math%2C - () https://www.npmjs.com/package/string-math%2C - Broken Link

30 Jun 2025, 19:15

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.0
CWE CWE-1333

30 Jun 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-30 17:15

Updated : 2025-10-18 01:41


NVD link : CVE-2025-45143

Mitre link : CVE-2025-45143

CVE.ORG link : CVE-2025-45143


JSON object : View

Products Affected

devrafalko

  • string-math
CWE
CWE-1333

Inefficient Regular Expression Complexity