CVE-2021-43306

Exponential ReDoS in jquery-validation

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the jquery-validation npm package, when an attacker is able to supply arbitrary input to the url2 method


We have discovered 177,374 live websites that are affected by CVE-2021-43306.

Run a Free Instant Scan




Affected Software

Product  jQuery Validation Plugin
Category jQuery Plugins
Vulnerable Domains177,374 live websites (30% of jQuery Validation Plugin install base)
Vulnerable Versions
  • from 0 through 1.19.4
Vulnerable Versions Count27 versions ( 73% of all versions)


Common Weakness Enumeration

CWE-1333 Inefficient Regular Expression Complexity



Details

  • Published - Jun 1, 2022
  • Updated - Sep 16, 2024

Credits

  • Denys Vozniuk from JFrog Security Research

Website Distribution by Country

Number of websites using CVE-2021-43306
United States70,684 websites



Germany10,229 websites
GB9,367 websites
France7,791 websites
Russia6,351 websites
Italy5,659 websites
Netherlands5,394 websites
Canada4,201 websites
India3,910 websites
Spain3,287 websites

Website Distribution by TLD

Number of websites using CVE-2021-43306
.com76,851 websites
.org8,661 websites
.co.uk6,202 websites
.ru5,235 websites
.de4,913 websites
.nl4,783 websites
.net4,096 websites
.it4,093 websites
.fr3,188 websites
.com.au2,857 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2021-43306

Top websites that are affected by CVE-2021-43306. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****************.com United States*,***
***************.com United States*,***
***********.net Portugal*,***
*****.com United States*,***
********.com United States*,***
****.org United States*,***
*******.com United States*,***
******.com United States*,***
***************.com Singapore*,***
***.**.uk GB*,***
See full domain list

FAQ

CVE-2021-43306 is Inefficient Regular Expression Complexity in jQuery Validation Plugin
A total of 177,374 websites have been identified as vulnerable to CVE-2021-43306, based on global website indexing conducted by WebTechSurvey.
The jQuery Validation Plugin is affected by the CVE-2021-43306 vulnerability.
jQuery Validation Plugin versions up to 1.19.4 are vulnerable to CVE-2021-43306.
CVE-2021-43306 is resolved in version 1.19.4 of jQuery Validation Plugin.