Vulnerabilities/

DOS by abusing `fetchOptions.retry`.

Severity:
High

Description

nuxt-api-party allows developers to proxy requests to an API without exposing credentials to the client. ofetch is used to send the requests.

The library allows the user to send many options directly to ofetch. There is no filter on which options are available. We can abuse the retry logic to cause the server to crash from a stack overflow.

Recommendation

Update the nuxt-api-party package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
nuxt-api-party
Anything's wrong? Let us know Last updated on December 13, 2023

This issue is available in SmartScanner Professional

See Pricing