CVE-2019-17592: Csv-Parse Project Csv-Parse
High severity, CVSS 7.5. EPSS: 2.3% chance of exploitation in the next 30 days.
The csv-parse module before 4.4.6 for Node.js is vulnerable to Regular Expression Denial of Service. The __isInt() function contains a malformed regular expression that processes large crafted input very slowly. This is triggered when using the cast option.
Affected products
- Csv-Parse Project Csv-Parse: before 4.4.6 (fixed in 4.4.6)
- Fedoraproject Fedora: version 31 only
Published 2019-10-14. Last modified 2026-06-17.