Snyk has a proof-of-concept or detailed explanation of how to exploit this vulnerability.
The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsLearn about Allocation of Resources Without Limits or Throttling vulnerabilities in an interactive lesson.
Start learningUpgrade org.webjars.npm:ip-address to version 10.7.2 or higher.
org.webjars.npm:ip-address is an A library for parsing IPv4 and IPv6 IP addresses in node and the browser.
Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via the Address6.isValid() method (and the Address4 constructor) when parsing an oversized input string. The bad-character diagnostic wraps every offending character in an HTML <span> element, so an N-byte string of punctuation produces approximately 106N bytes of output and triggers a synchronous String.replace over the entire result. An 8 MiB input takes roughly 529 ms and 895 MB of memory, a 16 MiB input causes a RangeError by exceeding V8's maximum string length, and a 32 MiB input causes V8 to abort the process entirely with a fatal invalid-size error.
Note: Material impact occurs only when an application accepts a very large attacker-controlled field and passes it to Address6 or Address4 parsing without an earlier length bound.