CVE-2024-27088

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
26/02/2024
Last modified:
05/02/2025

Description

es5-ext contains ECMAScript 5 extensions. Passing functions with very long names or complex default argument names into `function#copy` or `function#toStringTokens` may cause the script to stall. The vulnerability is patched in v0.10.63.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:medikoo:es5-ext:*:*:*:*:*:node.js:*:* 0.10.0 (including) 0.10.63 (excluding)