GHSA-7vxc-q7rv-qfj8
Dashboard / Vulnerabilities / GHSA-7vxc-q7rv-qfj8
Summary: SUCHMOKUO node-worker-threads-pool denial of service Vulnerability
Details: An issue was discovered in StaticPool in SUCHMOKUO node-worker-threads-pool version 1.4.3 that allows attackers to cause a denial of service. This can be mitigated by manually creating a timeout. For example: ```ts const { StaticPool } = require(\"node-worker-threads-pool\"); const staticPool = new StaticPool({ size: 1, task: (n) => { while (n) { console.log(\"a\"); } return n; } }); staticPool.createExecutor().setTimeout(10).exec(1).then((result) => { console.log(\"result from thread pool:\", result); }).catch(() => console.error('timeout')); ```
References: https://nvd.nist.gov/vuln/detail/CVE-2021-29057, https://github.com/SUCHMOKUO/node-worker-threads-pool/issues/20, https://github.com/SUCHMOKUO/node-worker-threads-pool
Affected packages
Package
Name: node-worker-threads-pool
Purl: pkg:npm/node-worker-threads-pool
Affected ranges
Type: SEMVER
Events:
