@swc/core is vulnerable to Denial of Service (DoS)
35
Low Risk
The SWC ECMAScript lexer and JSX parser panic when they decode a JSX text entity that resolves to a lone or invalid UTF-16 surrogate code point, crashing the process compiling the source file. Because @swc/core parses and transforms arbitrary JavaScript, TypeScript, and JSX source during builds, bundling, and CI pipelines, a crafted or malformed JSX file that reaches the compiler triggers this crash. The fix rejects the malformed surrogate entity with a parse error instead of panicking, avoiding the crash.
You are affected if you are using a version that falls within the vulnerable range, and you parse JSX source that may contain untrusted or externally supplied content.
@swc/core is vulnerable to Denial of Service (DoS) in versions 1.0.11 - 1.15.47.
Upgrade the @swc/core library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.