referencing is vulnerable to Stack-based Buffer Overflow
75
High Risk
Affected versions of this package are vulnerable to a Denial of Service (DoS) via Stack Overflow. An empty $ref value triggers infinite recursion during JSON Schema validation, eventually crashing the process. An attacker can exploit this by submitting a maliciously crafted schema containing {'$ref': ''}, consuming all available stack memory.
You are affected if you are using a version that falls within the vulnerable range.
referencing is vulnerable to Stack-based Buffer Overflow in versions 0.34.0 - 0.37.0.
Upgrade the referencing library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant