Foundation is a front-end framework. Versions 6.3.3 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, it is unknown if any fixes are available.
                
            Metrics
Affected Vendors & Products
References
        History
                    Sat, 12 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        epss
         
  | 
    
        
        
        epss
         
  | 
Wed, 13 Nov 2024 20:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Foundation foundation
         | 
|
| CPEs | cpe:2.3:a:foundation:foundation:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Foundation foundation
         | 
|
| Metrics | 
        
        cvssV3_1
         
  | 
Mon, 28 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Foundation
         Foundation foundation-sites  | 
|
| CPEs | cpe:2.3:a:foundation:foundation-sites:*:*:*:*:*:*:*:* | |
| Vendors & Products | 
        
        Foundation
         Foundation foundation-sites  | 
|
| Metrics | 
        
        ssvc
         
  | 
Sat, 26 Oct 2024 20:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Foundation is a front-end framework. Versions 6.3.3 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, it is unknown if any fixes are available. | |
| Title | GHSL-2020-290: Regular Expression Denial of Service (ReDoS) in foundation-sites | |
| Weaknesses | CWE-1333 | |
| References | 
         | |
| Metrics | 
        
        cvssV4_0
         
  | 
Status: PUBLISHED
Assigner: GitHub_M
Published: 2024-10-26T20:26:12.868Z
Updated: 2024-10-28T14:56:44.624Z
Reserved: 2020-10-01T00:00:00.000Z
Link: CVE-2020-26304
Updated: 2024-10-28T14:56:40.399Z
Status : Analyzed
Published: 2024-10-26T21:15:13.673
Modified: 2024-11-13T19:58:06.190
Link: CVE-2020-26304
No data.