Vulnerability library
Security checkJuly 05, 2024

Uncontrolled resource consumption in braces

Understand the exposure, see the recommended fix, and check whether your own website has related weaknesses.

High severitynpmbraces

Check your website

Find this and other vulnerabilities with a free scan.

Your scan runs on your computer. No account required.

Description

The NPM package braces fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In lib/parse.js, if a malicious user sends “imbalanced braces” as input, the parsing will enter a loop, which will cause the program to start allocating heap memory without freeing it at any moment of the loop.

Recommendation

Update the braces package to the latest compatible version. Followings are version details:

  • Affected version(s): < 3.0.3
  • Patched version(s): 3.0.3

References

Could your website be exposed too?

SmartScanner can check your website for Uncontrolled resource consumption in braces and gives you actionable findings to investigate.

Start a free scan

Related Issues

See something that needs correcting? Let us knowUpdated July 05, 2024