VDB
KO
MEDIUM 6.5

GHSA-grv6-m753-3w2g

NocoDB vulnerable to Denial of Service

Details

NocoDB prior to 0.92.0 allows actors to insert large characters into the input field `New Project` on the create field, which can cause a Denial of Service (DoS) via a crafted HTTP request. Version 0.92.0 fixes this issue.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / nocodb
Introduced in: 0 Fixed in: 0.92.0
Fix npm install nocodb@0.92.0

References