GHSA-7hpj-7hhx-2fgx
Dashboard / Vulnerabilities / GHSA-7hpj-7hhx-2fgx
Summary: msgpackr's conversion of property names to strings can trigger infinite recursion
Details: ### Impact When decoding user supplied MessagePack messages, users can trigger stuck threads by crafting messages that keep the decoder stuck in a loop. ### Patches The fix is available in v1.10.1 ### Workarounds Exploits seem to require structured cloning, replacing the 0x70 extension with your own (that throws an error or does something other than recursive referencing) should mitigate the issue. ### References
References: https://github.com/kriszyp/msgpackr/security/advisories/GHSA-7hpj-7hhx-2fgx, https://nvd.nist.gov/vuln/detail/CVE-2023-52079, https://github.com/kriszyp/msgpackr/commit/18f44f8800e2261341cdf489d1ba1e35a0133602, https://github.com/kriszyp/msgpackr
Affected packages
Package
Name: msgpackr
Purl: pkg:npm/msgpackr
Affected ranges
Type: SEMVER
Events:
