Intel

AIKIDO-2026-10128

sync-message-port is vulnerable to Denial of Service (DoS)

Denial of Service (DoS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

22

Low Risk

This Affects:

JSsync-message-port
0.0.1 - 1.1.3
Fixed in 1.2.0

TL;DR

Affected versions of this package contain a race condition in the synchronous message-port implementation that can lead to counter underflow and inconsistent message state, resulting in unexpected crashes. This issue can be triggered to cause a denial of service by repeatedly hitting the faulty code path.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

sync-message-port is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 1.1.3.

How to fix this

Upgrade the sync-message-port library to the patch version.

Background Info