VDB
Sign up
LOW3.7

GHSA-r5w7-f542-q2j4

Potential DoS when using ContextLines integration

Quick fix

GHSA-r5w7-f542-q2j4 — @sentry/node: upgrade to the fixed version with the command below.

npm install @sentry/node@8.49.0

Details

### Impact The [ContextLines integration](https://docs.sentry.io/platforms/javascript/guides/node/configuration/integrations/contextlines/) uses readable streams to more efficiently use memory when reading files. The ContextLines integration is used to attach source context to outgoing events.

The stream was not explicitly closed after use. This could lead to excessive amounts of file handles open on the system and potentially lead to a Denial of Service (DoS).

The ContextLines integration is enabled by default in the Node SDK (`@sentry/node`) and SDKs that run in Node.js environments (`@sentry/astro`, `@sentry/aws-serverless`, `@sentry/bun`, `@sentry/google-cloud-serverless`, `@sentry/nestjs`, `@sentry/nextjs`, `@sentry/nuxt`, `@sentry/remix`, `@sentry/solidstart`, `@sentry/sveltekit`).

### Patches

Users should upgrade to version `8.49.0` or higher.

### Workarounds

To remediate this issue in affected versions without upgrading to version `8.49.0` and above you can disable the ContextLines integration. See the [docs](https://docs.sentry.io/platforms/javascript/guides/node/configuration/integrations/#removing-a-default-integration) for more details.

```js Sentry.init({ // ... integrations: function (integrations) { // integrations will be all default integrations return integrations.filter(function (integration) { return integration.name !== "ContextLines"; }); }, }); ```

If you disable the ContextLines integration, you will lose source context on your error events.

### References - Reported issue: https://github.com/getsentry/sentry-javascript/issues/14892 - PR Fix: https://github.com/getsentry/sentry-javascript/pull/14997

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/@sentry/node
Introduced in: 8.10.0Fixed in: 8.49.0
Fixnpm install @sentry/node@8.49.0
npm/@sentry/astro
Introduced in: 8.10.0Fixed in: 8.49.0
Fixnpm install @sentry/astro@8.49.0
npm/@sentry/aws-serverless
Introduced in: 8.10.0Fixed in: 8.49.0
Fixnpm install @sentry/aws-serverless@8.49.0
npm/@sentry/bun
Introduced in: 8.10.0Fixed in: 8.49.0
Fixnpm install @sentry/bun@8.49.0
npm/@sentry/google-cloud-serverless
Introduced in: 8.10.0Fixed in: 8.49.0
Fixnpm install @sentry/google-cloud-serverless@8.49.0
npm/@sentry/nestjs
Introduced in: 8.10.0Fixed in: 8.49.0
Fixnpm install @sentry/nestjs@8.49.0
npm/@sentry/nextjs
Introduced in: 8.10.0Fixed in: 8.49.0
Fixnpm install @sentry/nextjs@8.49.0
npm/@sentry/nuxt
Introduced in: 8.10.0Fixed in: 8.49.0
Fixnpm install @sentry/nuxt@8.49.0
npm/@sentry/remix
Introduced in: 8.10.0Fixed in: 8.49.0
Fixnpm install @sentry/remix@8.49.0
npm/@sentry/solidstart
Introduced in: 8.10.0Fixed in: 8.49.0
Fixnpm install @sentry/solidstart@8.49.0
npm/@sentry/sveltekit
Introduced in: 8.10.0Fixed in: 8.49.0
Fixnpm install @sentry/sveltekit@8.49.0

References