VYPR
High severity7.5NVD Advisory· Published May 14, 2024· Updated Jun 17, 2026

CVE-2024-4068

CVE-2024-4068

Description

The NPM package braces, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In lib/parse.js, if a malicious user sends "imbalanced braces" as input, the parsing will enter a loop, which will cause the program to start allocating heap memory without freeing it at any moment of the loop. Eventually, the JavaScript heap limit is reached, and the program will crash.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
bracesnpm
< 3.0.33.0.3

Affected products

99

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.