GHSA-grv7-fg5c-xmjg
HIGHCVE-2024-4068The NPM package braces fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In lib/parse.js, if a malicious user sends "imbalanced braces" as input, the parsing will enter a loop, which will cause the program to start allocating heap memory without freeing it at any moment of the loop. Eventually, the JavaScript heap limit is reached, and the program will c
- Affected
- < 3.0.3
- Fixed in
- 3.0.3
- Weakness
- CWE-400
- Published
- 2024-05-14
- Source
- github
GHSANVDMITREreferencereferencereferencereferencereferencereference