@discordjs/opus/.../opus@0.5.2 vulnerabilities

Opus bindings for Node

Direct Vulnerabilities

Known vulnerabilities in the @discordjs/opus package. This does not include vulnerabilities belonging to this package’s dependencies.

How to fix?

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

Fix for free
VulnerabilityVulnerable Version
  • H
Denial of Service (DoS)

@discordjs/opus is a native bindings to libopus.

Affected versions of this package are vulnerable to Denial of Service (DoS) due to providing an input object with a property toString to several different functions. Exploiting this vulnerability could lead to a system crash.

How to fix Denial of Service (DoS)?

There is no fixed version for @discordjs/opus.

*
  • H
Denial of Service (DoS)

@discordjs/opus is a native bindings to libopus.

Affected versions of this package are vulnerable to Denial of Service (DoS) when trying to encode using an encoder with zero channels, or a non-initialized buffer. This leads to a hard crash.

How to fix Denial of Service (DoS)?

Upgrade @discordjs/opus to version 0.8.0 or higher.

<0.8.0