CVE-2020-28469: Regular Expression Denial of Service (ReDoS)

Published Jan 12, 2021
·
Updated

A flaw was found in nodejs-glob-parent. The enclosure regex used to check for glob enclosures containing backslashes is vulnerable to Regular Expression Denial of Service attacks. This flaw allows an attacker to cause a denial of service if they can supply a malicious string to the glob-parent function. The highest threat from this vulnerability is to system availability.

Other sources

Node.js glob-parent module is vulnerable to a denial of service. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause a regular expression denial of service.

IBM

The enclosure regex used to check for glob enclosures containing backslash is vulnerable to Regular Expression Denial of Service attacks. An attacker can use this flaw to cause a denial of service if they can supply a malicious string to the glob-parent function.

Red Hat

This affects the package glob-parent before 5.1.2. The enclosure regex used to check for strings ending in enclosure containing path separator.

Affected Software

12 affected componentsFixes available
redhat/nodejs-nodemon<0:2.0.19-1.el9_0
0:2.0.19-1.el9_0
redhat/rh-nodejs14-nodejs-nodemon<0:2.0.3-5.el7
0:2.0.3-5.el7
redhat/rh-nodejs12-nodejs<0:12.22.5-1.el7
0:12.22.5-1.el7
redhat/rh-nodejs12-nodejs-nodemon<0:2.0.3-5.el7
0:2.0.3-5.el7
redhat/ovirt-engine-ui-extensions<0:1.2.7-1.el8e
0:1.2.7-1.el8e
redhat/ovirt-web-ui<0:1.7.2-1.el8e
0:1.7.2-1.el8e
redhat/nodejs-glob-parent<5.1.2
5.1.2
npm/glob-parent>=4.0.0<5.1.2
5.1.2
gulpjs Glob-parent Node.js<5.1.2
Oracle Communications Cloud Native Core Policy=1.14.0
IBM Cognos Analytics<=11.2.0 - 11.2.2
IBM Cognos Analytics<=11.1.0 - 11.1.6 FP4

Event History

Jan 12, 2021
CVE Published
12:00 AM
Apr 1, 2021
Data Sourced
via Red Hat·01:08 AM
DescriptionSeverityAffected Software
Jun 3, 2021
CVE Published
via MITRE·03:15 PM
Data Sourced
via MITRE·03:15 PM
DescriptionSeverityWeakness
Jun 7, 2021
Advisory Published
via GitHub·09:56 PM
Feb 23, 2026
Data Sourced
via IBM·11:32 PM
DescriptionAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is CVE-2020-28469?

CVE-2020-28469 is a vulnerability in the package glob-parent before version 5.1.2. It is susceptible to Regular Expression Denial of Service (ReDoS) attacks.

2

How does CVE-2020-28469 impact the nodejs-glob-parent package?

CVE-2020-28469 allows an attacker to cause a denial of service by supplying a malicious string to the glob-parent function.

3

What is the severity of CVE-2020-28469?

CVE-2020-28469 has a severity rating of 7.5 (high).

4

How can I fix CVE-2020-28469?

To fix CVE-2020-28469, update the glob-parent package to version 5.1.2 or higher.

5

Where can I find more information about CVE-2020-28469?

You can find more information about CVE-2020-28469 at the following references: [CVE-2020-28469](https://www.cve.org/CVERecord?id=CVE-2020-28469), [NVD](https://nvd.nist.gov/vuln/detail/CVE-2020-28469), [Snyk](https://snyk.io/vuln/SNYK-JS-GLOBPARENT-1016905), [Red Hat Bugzilla](https://bugzilla.redhat.com/show_bug.cgi?id=1945459), [Red Hat Security Advisory](https://access.redhat.com/errata/RHSA-2021:3016).

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203