jaq-core is vulnerable to Denial of Service (DoS)
20
Low Risk
Affected versions of this package may panic when processing input containing invalid UTF-8 characters. If an attacker can supply malformed or non-UTF-8 encoded data, the application may encounter an unexpected runtime panic, potentially leading to a denial of service. This occurs because the package does not properly validate or handle invalid UTF-8 sequences before attempting operations that assume valid encoding.
You are affected if you are using a version that falls within the vulnerable range and overflow checking is enabled.
jaq-core is vulnerable to Denial of Service (DoS) in versions 1.6.0 - 2.1.1.
Upgrade the jaq-core library to the patch version or turn off overflow checking.
Secure your code, cloud, and runtime environments in one central system. Find and fix vulnerabilities automatically.
No credit card required | Scan results in 32secs.
SOC 2Compliant
ISO 27001Compliant