Node.js WebCrypto and Node-tar Libraries Disclose Multiple Denial of Service Flaws
Sourced from 1 publication
- •A flaw in Node.js WebCrypto allows process crashes when subtle.encrypt receives input exceeding 2 GB.
- •A crafted gzip bomb can exhaust disk space and CPU resources in the node-tar library due to weak processing limits.
- •A malformed tar archive header with a negative entry size triggers an infinite loop in node-tar's archive scanner.
- •All three vulnerabilities are denial of service vectors requiring specially crafted attacker input.
Sources
Curated from 1 sources. Every summary is reviewed for accuracy, but may still contain errors. We always link to original sources for verification.
Related Stories
About Meridian
Meridian is a free daily newsletter delivering signal-scored news stories with forward-looking analysis every morning. Stories are scored across six criteria (global leverage, capital impact, temporal durability, career relevance, decision utility, and narrative clarity) then assigned to Big Signal, Core, or Quick tiers.
Get Meridian in your inbox
The stories that matter, every morning at 06:00.