漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
toml-node: Uncontrolled Recursion
Vulnerability Description
toml-node is a TOML parser for Node.js and the browser. Prior to 4.2.0, toml.parse() uses a Peggy 5.1.0 generated recursive-descent parser in lib/parser.js whose peg$parsevalue, peg$parsearray, and peg$parseinline_table_entry functions recurse through nested arrays and inline tables without a depth limit. A remote unauthenticated application parsing an attacker-controlled TOML document containing a few thousand nested arrays or inline tables can exhaust the Node.js call stack, raise an unexpected RangeError rather than the parser's SyntaxError, and terminate an unprotected request worker or process. The corresponding grammar source is src/toml.pegjs, where the generated parser must be bounded. This issue is fixed in version 4.2.0.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Vulnerability Type
未经控制的递归
Vulnerability Title
Michelle Tilley TOML Parser for Node.js 资源管理错误漏洞
Vulnerability Description
Michelle Tilley TOML Parser for Node.js是Michelle Tilley个人开发者的一款TOML格式解析器。 Michelle Tilley TOML Parser for Node.js 4.2.0之前版本存在资源管理错误漏洞,该漏洞源于解析器在解析嵌套数组和内联表时未设置深度限制,可能耗尽Node.js调用栈并导致拒绝服务。
CVSS Information
N/A
Vulnerability Type
N/A