CVE-2020-28500

Regular Expression Denial of Service (ReDoS)

Lodash versions prior to 4.17.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the toNumber, trim and trimEnd functions.


We have discovered 581,995 live websites that are affected by CVE-2020-28500.

Run a Free Instant Scan




Affected Software

Product  Lodash
Category JavaScript Libraries
Vulnerable Domains581,995 live websites (37% of Lodash install base)
Vulnerable Versions
  • from 4.17.21 through 4.17.21
Vulnerable Versions Count1 versions ( 2.44% of all versions)



Details

  • Published - Feb 15, 2021
  • Updated - Sep 16, 2024

Credits

  • Liyuan Chen

Website Distribution by Country

Number of websites using CVE-2020-28500
United States71,328 websites



Israel416,005 websites
GB12,881 websites
Germany11,719 websites
Italy5,990 websites
France5,891 websites
Switzerland4,730 websites
Japan4,615 websites
Brazil3,978 websites
Australia3,918 websites

Website Distribution by TLD

Number of websites using CVE-2020-28500
.com327,687 websites
.org39,835 websites
.co.uk36,290 websites
.net20,570 websites
.de13,460 websites
.com.au11,405 websites
.com.br10,862 websites
.ca9,301 websites
.ch8,238 websites
.fr7,969 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2020-28500

Top websites that are affected by CVE-2020-28500. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.com United States***
***.***.edu United States*,***
************.com China*,***
*************.uk United States*,***
***.org United States*,***
*******.org United States*,***
*****.***.cn United States*,***
*********.com United States*,***
********.ru Russia*,***
****.*******.edu United States*,***
See full domain list

FAQ

A total of 581,995 websites have been identified as vulnerable to CVE-2020-28500, based on global website indexing conducted by WebTechSurvey.
The Lodash is affected by the CVE-2020-28500 vulnerability.
Lodash versions up to and including 4.17.21 are vulnerable to CVE-2020-28500.

References