Intel

AIKIDO-2026-140382

cron-parser is vulnerable to Denial of Service (DoS)

Denial of Service (DoS)GHSA-r9w7-75q6-r884 Published Yesterday

53

Medium Risk

This Affects:

JScron-parser
0.0.1 - 5.10.0
Fixed in 5.10.1
Are you affected? Scan for Free

TL;DR

CronExpressionParser.parse() expands a cron field containing a repeated wildcard list token (*,*,*,...) into one array element per repetition, with no cap on field length. A crafted expression of a few hundred kilobytes allocates tens of millions of elements in one synchronous call, exhausting the Node.js heap and aborting the process. Any caller that parses a cron expression from an untrusted submitter, such as a user supplied schedule string, can trigger this crash. The fix caps field expansion at 256 values and rejects expressions that exceed it.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

cron-parser is vulnerable to Denial of Service (DoS) in versions 0.0.1 - 5.10.0.

How to fix this

Upgrade the cron-parser library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform