-
Notifications
You must be signed in to change notification settings - Fork 41
Open
Description
What happened?
Hi,
IMO this fork of https://github.com/kangax/html-minifier is still vulnerable to CVE-2022-37620 as the regex in the candidate variable is still the same.
References :
https://nvd.nist.gov/vuln/detail/CVE-2022-37620
kangax/html-minifier#1135
Version
All
What browsers are you seeing the problem on?
No response
Link to reproduce
No response
Relevant log output
No response
Willing to submit a PR?
None
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
No labels