node-liblzma is vulnerable to Denial of Service
45
Medium Risk
Decoder helpers accepted caller-supplied memory ceilings straight through numeric coercion without rejecting NaN, Infinity, negatives, or oversized bigint representations ahead of WASM or native stream wiring. That breaks the expectation that resource limits are strict operator-controlled budgets for hostile-automation scenarios feeding crafted option bags. Validation now fails closed before allocating decoder state across both WASM shims and N-API bindings.
You are affected if you are using a version that falls within the vulnerable range.
node-liblzma is vulnerable to Denial of Service in versions 3.0.0 - 5.0.0.
Upgrade the node-liblzma library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant