An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the jquery-validation npm package, when an attacker is able to supply arbitrary input to the url2 method
We have discovered 177,374 live websites that are affected by CVE-2021-43306.
| Product | |
| Category | jQuery Plugins |
| Vulnerable Domains | 177,374 live websites (30% of jQuery Validation Plugin install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 27 versions ( 73% of all versions) |
| 70,684 websites | |
| 10,229 websites | |
| 9,367 websites | |
| 7,791 websites | |
| 6,351 websites | |
| 5,659 websites | |
| 5,394 websites | |
| 4,201 websites | |
| 3,910 websites | |
| 3,287 websites |
| .com | 76,851 websites |
| .org | 8,661 websites |
| .co.uk | 6,202 websites |
| .ru | 5,235 websites |
| .de | 4,913 websites |
| .nl | 4,783 websites |
| .net | 4,096 websites |
| .it | 4,093 websites |
| .fr | 3,188 websites |
| .com.au | 2,857 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****************.com | *,*** | ||
| ***************.com | *,*** | ||
| ***********.net | *,*** | ||
| *****.com | *,*** | ||
| ********.com | *,*** | ||
| ****.org | *,*** | ||
| *******.com | *,*** | ||
| ******.com | *,*** | ||
| ***************.com | *,*** | ||
| ***.**.uk | *,*** |
FAQ