Intel

AIKIDO-2026-193864

@swc/core is vulnerable to Denial of Service (DoS)

Denial of Service (DoS) Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.
Published 2 days ago

35

Low Risk

This Affects:

JS@swc/core
1.0.11 - 1.15.47
Fixed in 1.16.0
Are you affected? Scan for Free

TL;DR

The SWC ECMAScript lexer and JSX parser panic when they decode a JSX text entity that resolves to a lone or invalid UTF-16 surrogate code point, crashing the process compiling the source file. Because @swc/core parses and transforms arbitrary JavaScript, TypeScript, and JSX source during builds, bundling, and CI pipelines, a crafted or malformed JSX file that reaches the compiler triggers this crash. The fix rejects the malformed surrogate entity with a parse error instead of panicking, avoiding the crash.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range, and you parse JSX source that may contain untrusted or externally supplied content.

Background info

@swc/core is vulnerable to Denial of Service (DoS) in versions 1.0.11 - 1.15.47.

How to fix this

Upgrade the @swc/core library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform