GHSA-hp3w-g68c-fv3c

Suggest an improvement
Source
https://github.com/advisories/GHSA-hp3w-g68c-fv3c
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-hp3w-g68c-fv3c/GHSA-hp3w-g68c-fv3c.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-hp3w-g68c-fv3c
Aliases
Downstream
CGA (2)
Published
2026-09-24T15:31:31Z
Modified
2026-10-06T00:00:08Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
  • 6.9 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N CVSS Calculator
Summary
sprintf-js vulnerable to denial of service through unbounded precision specifiers
Details

sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions. Attackers who control format strings can inject precision values exceeding ECMAScript limits to abort calling operations with minimal payload.

Database specific
{
    "cwe_ids":  [
        "CWE-1284"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-10-05T23:47:34Z",
    "nvd_published_at":  "2026-09-24T14:18:21Z",
    "severity":  "MODERATE"
}
References

Affected packages

npm / sprintf-js

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
1.1.3

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-hp3w-g68c-fv3c/GHSA-hp3w-g68c-fv3c.json"