Vulnerabilities/

Denial of Service in mem

Severity:
Medium

Description

Versions of mem prior to 4.0.0 are vulnerable to Denial of Service (DoS). The package fails to remove old values from the cache even after a value passes its maxAge property. This may allow attackers to exhaust the system’s memory if they are able to abuse the application logging.

Recommendation

Update the mem package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
mem
Anything's wrong? Let us know Last updated on January 09, 2023