GHSA-773h-w45w-f2f9
Dashboard / Vulnerabilities / GHSA-773h-w45w-f2f9
GHSA-773h-w45w-f2f9
Summary: Denial of service vulnerability exists in libxmljs
Details: libxmljs provides libxml bindings for v8 javascript engine. This affects all versions of package libxmljs. When invoking the libxmljs.parseXml function with a non-buffer argument the V8 code will attempt invoking the .toString method of the argument. If the argument's toString value is not a Function object V8 will crash.
References: https://nvd.nist.gov/vuln/detail/CVE-2022-21144, https://github.com/libxmljs/libxmljs/pull/594, https://github.com/libxmljs/libxmljs/commit/2501807bde9b38cfaed06d1e140487516d91379d, https://github.com/libxmljs/libxmljs, https://snyk.io/vuln/SNYK-JS-LIBXMLJS-2348756
Affected packages
Package
Name: libxmljs
Purl: pkg:npm/libxmljs
Affected ranges
Type: SEMVER
Events:
