High severity7.5NVD Advisory· Published Aug 29, 2022· Updated Jun 17, 2026
CVE-2022-36034
CVE-2022-36034
Description
nitrado.js is a type safe wrapper for the Nitrado API. Possible ReDoS with lib input of {{ and with many repetitions of {{|. This issue has been patched in all versions above 0.2.5. There are currently no known workarounds.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
nitrado.jsnpm | < 0.2.5 | 0.2.5 |
Affected products
3- Range: < 0.2.5
- cpe:2.3:a:nitrado.js_project:nitrado.js:*:*:*:*:*:node.js:*:*Range: <0.2.5
Patches
Vulnerability mechanics
References
4- github.com/advisories/GHSA-vqc4-v8hc-h2jgghsaADVISORY
- github.com/cainthebest/nitrado.js/blob/v0.2.5/CHANGELOG.mdnvdRelease NotesThird Party AdvisoryWEB
- github.com/cainthebest/nitrado.js/security/advisories/GHSA-vqc4-v8hc-h2jgnvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2022-36034ghsaADVISORY
News mentions
0No linked articles in our index yet.