1 known bug in negotiator, with affected versions, fixes and workarounds. Sourced from upstream issue trackers.
| Severity | Affected | Fixed in | Title | Status | Source |
|---|---|---|---|---|---|
| high | any | 0.6.1 | Regular Expression Denial of Service in negotiator Affected versions of `negotiator` are vulnerable to regular expression denial of service attacks, which trigger upon parsing a specially crafted `Accept-Language` header value.
## Recommendation
Update to version 0.6.1 or later. | fixed | osv:GHSA-7mc5-chhp-fmc3 |
Get this data programmatically \u2014 free, no authentication.
curl https://depscope.dev/api/bugs/npm/negotiator