Description
Versions of mem prior to 4.0.0 are vulnerable to Denial of Service (DoS). The package fails to remove old values from the cache even after a value passes its maxAge property. This may allow attackers to exhaust the system’s memory if they are able to abuse the application logging.
Recommendation
Update the mem package to the latest compatible version. Followings are version details:
- Affected version(s): < 4.0.0
- Patched version(s): 4.0.0
References
Related Issues
- Knwl.js Regular Expression Denial of Service vulnerability - CVE-2020-26306
- Regular Expression Denial of Service in marked - marked - GHSA-ch52-vgq2-943f - Vulnerability
- Regular Expression Denial of Service in clean-css - Vulnerability
- Zod denial of service vulnerability - CVE-2023-4316
You might also like:
- Tags:
- npm
- mem
Anything's wrong? Let us know Last updated on January 09, 2023


