Mend.io Vulnerability Database
The largest open source vulnerability database
What is a Vulnerability ID?
New vulnerability? Tell us about it!
CVE-2024-27088
February 26, 2024
es5-ext contains ECMAScript 5 extensions. Passing functions with very long names or complex default argument names into "function#copy" or "function#toStringTokens" may cause the script to stall. The vulnerability is patched in v0.10.63.
Additional Notes
The description of this vulnerability differs from MITRE.
Do you need more information?
Contact Us
Weakness Type (CWE)
Inefficient Regular Expression Complexity
Uncontrolled Resource Consumption
EPSS
Base Score:
1.85