@solana/web3.js@0.97.0 vulnerabilities

Solana Javascript API

Direct Vulnerabilities

Known vulnerabilities in the @solana/web3.js package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • H
Improper Restriction of Operations within the Bounds of a Memory Buffer

@solana/web3.js is a Solana Javascript API

Affected versions of this package are vulnerable to Improper Restriction of Operations within the Bounds of a Memory Buffer due to the deserialization of the Message/Transaction object. Using specific inputs can lead to memory exhaustion and potentially crash the application or service, resulting in a loss of availability.

How to fix Improper Restriction of Operations within the Bounds of a Memory Buffer?

Upgrade @solana/web3.js to version 1.91.3 or higher.

<1.91.3