joserfc is vulnerable to Uncontrolled Resource Consumption
20
Low Risk
Affected versions of this package are vulnerable to Denial of Service due to insufficient content size validation in JWS and JWE components. The vulnerability allows attackers to send gigantic JWS or JWE payloads that are processed without size checks, consuming excessive memory and CPU resources. An attacker can exploit this by crafting large messages that overwhelm the system during parsing, potentially leading to service unavailability or crashes.
You are affected if you are using a version that falls within the vulnerable range.
joserfc is vulnerable to Uncontrolled Resource Consumption in versions 1.2.0 - 1.3.3.
Upgrade the joserfc library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant