VDB
Sign up
MEDIUM

GHSA-hvq2-wf92-j4f3

express-xss-sanitizer has an unbounded recursion depth

Quick fix

GHSA-hvq2-wf92-j4f3 — express-xss-sanitizer: upgrade to the fixed version with the command below.

npm install express-xss-sanitizer@2.0.1

Details

# Security Advisory: express-xss-sanitizer

## Overview A vulnerability was discovered in express-xss-sanitizer that allowed unbounded recursion depth during sanitization of nested objects.

## Affected Versions - All versions prior to 2.0.1

## Patched Versions - 2.0.1 and later

## Description The sanitize function in lib/sanitize.js performed recursive sanitization without depth limiting, making it vulnerable to stack overflow attacks via specially crafted deeply nested JSON objects.

## Impact An attacker could cause denial-of-service by sending a request with deeply nested structures, potentially crashing the Node.js process.

## Solution Upgrade to version 2.0.1 or later:

```bash npm install express-xss-sanitizer@latest ```

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/express-xss-sanitizer
Introduced in: 0Fixed in: 2.0.1
Fixnpm install express-xss-sanitizer@2.0.1

References