Description
Versions of mem prior to 4.0.0 are vulnerable to Denial of Service (DoS). The package fails to remove old values from the cache even after a value passes its maxAge property. This may allow attackers to exhaust the system’s memory if they are able to abuse the application logging.
Recommendation
Update the mem package to the latest compatible version. Followings are version details:
- Affected version(s): < 4.0.0
- Patched version(s): 4.0.0
References
Could your website be exposed too?
SmartScanner can check your website for Denial of Service in mem and gives you actionable findings to investigate.
Start a free scanRelated Issues
- Knwl.js Regular Expression Denial of Service vulnerability - CVE-2020-26306
- Regular Expression Denial of Service in marked - marked - GHSA-ch52-vgq2-943f - Vulnerability
- Regular Expression Denial of Service in clean-css - Vulnerability
- Zod denial of service vulnerability - CVE-2023-4316


