herb is vulnerable to Denial of Service (DoS)
28
Low Risk
Affected versions of this package are vulnerable to Denial of Service (DoS) due to a memory leak in the herb_parse and analyze.c components. An attacker can exploit this flaw by triggering repeated parsing or analysis operations, causing the application’s memory usage to grow over time. This can lead to resource exhaustion, degraded performance, or a complete service crash.
You are affected if you are using a version that falls within the vulnerable range.
herb is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 0.7.5.
Upgrade the herb library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant