referencing is vulnerable to Stack-based Buffer Overflow
75
High Risk
Affected versions of this package are vulnerable to a Denial of Service (DoS) via Stack Overflow. An empty $ref value triggers infinite recursion during JSON Schema validation, eventually crashing the process. An attacker can exploit this by submitting a maliciously crafted schema containing {'$ref': ''}, consuming all available stack memory.
You are affected if you are using a version that falls within the vulnerable range.
referencing is vulnerable to Stack-based Buffer Overflow in versions 0.34.0 - 0.37.0.
Upgrade the referencing library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant