Vulnerabilities/

msgpackr's conversion of property names to strings can trigger infinite recursion

Severity:
High

Description

When decoding user supplied MessagePack messages, users can trigger stuck threads by crafting messages that keep the decoder stuck in a loop.

Recommendation

Update the msgpackr package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
msgpackr
Anything's wrong? Let us know Last updated on January 10, 2024

This issue is available in SmartScanner Professional

See Pricing