VDB
Sign up
MEDIUM

GHSA-f52g-6jhx-586p

Denial of Service in handlebars

Quick fix

GHSA-f52g-6jhx-586p — handlebars: upgrade to the fixed version with the command below.

npm install handlebars@4.4.5

Details

Affected versions of `handlebars` are vulnerable to Denial of Service. The package's parser may be forced into an endless loop while processing specially-crafted templates. This may allow attackers to exhaust system resources leading to Denial of Service.

## Recommendation

Upgrade to version 4.4.5 or later.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/handlebars
Introduced in: 4.0.0Fixed in: 4.4.5
Fixnpm install handlebars@4.4.5

References