CVE-2023-26115: High severity wordwrap vulnerability
Published Jun 22, 2023
·Updated
A flaw was found in the Node.js word-wrap module, where it is vulnerable to a denial of service caused by a Regular expression denial of service (ReDoS) issue in the result variable. By sending a specially crafted regex input, a remote attacker can cause a denial of service.
Other sources
All versions of the package word-wrap are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of an insecure regular expression within the result variable.
Affected Software
7 affected componentsFixes available
npm/word-wrap<1.2.4
1.2.4
Word-wrap Project Word-wrap Node.js<1.2.4
Word-wrap Project Word-wrap Node.js
redhat/word-wrap<1.2.4
1.2.4
IBM Business Automation Insights<=25.0.0
IBM Business Automation Insights<=24.0.1
IBM Business Automation Insights<=24.0.0
Event History
Jun 22, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
RemedyDescriptionSeverityWeaknessAffected Software
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
DescriptionSeverityWeakness
Advisory Published
via GitHub·06:30 AM
Data Sourced
via Red Hat·07:29 PM
DescriptionSeverityAffected Software
Nov 3, 2025
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software
Parent advisories
This vulnerability appears in the following advisories.