@logtape/syslog is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection')
86
High Risk
@logtape/syslog allowed structured data values containing C0 control characters to inject forged syslog frames when SyslogSinkOptions.includeStructuredData was enabled. The fix sanitizes structured data values by escaping control characters into printable #NNN sequences and skips structured-data parameters with invalid RFC 5424 SD-NAME keys, preventing frame/control injection.
You are affected if you are using a version that falls within the vulnerable range.
@logtape/syslog is vulnerable to Improper Neutralization of CRLF Sequences ('CRLF Injection') in versions 0.0.0 - 1.3.10, 2.0.0 - 2.0.13 and 2.1.0 - 2.1.4.
Upgrade the @logtape/syslog library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant