GHSA-2mvq-xp48-4c77

Suggest an improvement
Source
https://github.com/advisories/GHSA-2mvq-xp48-4c77
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-2mvq-xp48-4c77/GHSA-2mvq-xp48-4c77.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-2mvq-xp48-4c77
Published
2020-09-03T20:35:29Z
Modified
2021-09-29T18:37:04Z
Summary
Denial of Service in subtext
Details

All versions of subtext are vulnerable to Denial of Service (DoS). The package fails to enforce the maxBytes configuration for payloads with chunked encoding that are written to the file system. This allows attackers to send requests with arbitrary payload sizes, which may exhaust system resources leading to Denial of Service.

Recommendation

This package is not actively maintained and has been moved to @hapi/subtext where version 6.1.2.

Database specific
{
    "cwe_ids": [
        "CWE-400"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2020-08-31T18:49:45Z",
    "nvd_published_at": null,
    "severity": "HIGH"
}
References

Affected packages

npm / subtext

Package

Affected ranges

Type
SEMVER
Events
Introduced
0.0.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/09/GHSA-2mvq-xp48-4c77/GHSA-2mvq-xp48-4c77.json"