Advisories for Npm/Uglify-Js package

2022
2017

Regular Expression Denial of Service

uglify-js is vulnerable to regular expression denial of service (ReDoS) when certain types of input is passed into .parse(). A regular expression leading to a very long processing time can be used to make the program hang for a very long time.

2015