Intel

AIKIDO-2024-10069

mappersmith is vulnerable to Memory Leak

Memory Leak Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published Apr 30, 2024

54

Medium Risk

This Affects:

JSmappersmith
2.28.0 - 2.42.0
Fixed in 2.43.0
Are you affected? Scan for Free

TL;DR

Affected versions of the mappersmith library are vulnerable to memory leaks when using an HTTP(s) agent with keep-alive=true. The TCP socket events are registered once per API call, which can lead to excessive memory usage.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

mappersmith is vulnerable to Memory Leak in versions 2.28.0 - 2.42.0.

How to fix this

Upgrade the mappersmith library to the patch version.