VDB
Sign up
MEDIUM4.4

GHSA-m2r3-8492-vx59

Denial of Service (DoS) in mongo-express

Details

All versions of package mongo-express are vulnerable to Denial of Service (DoS) when exporting an empty collection as CSV, due to an unhandled exception, leading to a crash.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/mongo-express
Introduced in: 0

No fixed version published yet for mongo-express (npm). Pin to a known-safe version or switch to an alternative.

References