Junglewise Threat Intelligence

CVE-2026-5986: Zod jsVideoUrlParser ReDoS in getTime function

CVE-2026-5986 · Severity: medium · CVSS 5.3 · Published 2026-04-10

Vendors: npm.

Executive brief

A denial-of-service vulnerability exists in js-video-url-parser, a library used to extract information like video IDs and timestamps from URLs. By providing a specially crafted video URL with a malicious timestamp parameter, an attacker can cause the application to freeze or become unresponsive. This can lead to a disruption of service for users of applications that rely on this library to process video links.

Technical details

A Regular Expression Denial of Service (ReDoS) vulnerability exists in js-video-url-parser versions 0.1.3 through 0.5.1. The getTime() function in lib/util.js uses an inefficient regular expression (/^(\d+[smhdw]?)+$/) to validate timestamp parameters. Due to nested quantifiers, a crafted string with a long sequence of digits followed by an invalid character triggers catastrophic backtracking. An unauthenticated remote attacker can exploit this by supplying a malicious 't' or 'start' parameter to any application calling urlParser.parse(), causing the Node.js event loop to block and resulting in a denial of service. As of the advisory date, no patch is available and the repository has been archived.

Affected products

  • Zod js-video-url-parser 0.1.3 to 0.5.1

Timeline

  • 2026-03-28: disclosed: Issue reported on GitHub repository
  • 2026-04-09: advisory: NVD publication date
  • 2026-04-10: advisory: GitHub Advisory published
  • 2026-04-24: other: GitHub repository archived by owner

References