A vulnerability, which was classified as problematic, has been found in Zod jsVideoUrlParser up to 0.5.1. The impacted element is the function
getTime in the library lib/util.js. This manipulation of the argument timestamp causes inefficient regular expression complexity.
The identification of this vulnerability is CVE-2026-5986. It is possible to initiate the attack remotely. Furthermore, there is an exploit available.
The project was informed of the problem early through an issue report but has not responded yet.