VYPR

Braces

by Jonschlinkert

CVEs (1)

  • CVE-2024-4068HigMay 14, 2024
    risk 0.42cvss 7.5epss 0.01

    The NPM package `braces`, versions prior to 3.0.3, fails to limit the number of characters it can handle, which could lead to Memory Exhaustion. In `lib/parse.js,` if a malicious user sends "imbalanced braces" as input, the parsing will enter a loop, which will cause the program…