#VU88394 Resource exhaustion in es5-ext - CVE-2024-27088
Published: April 10, 2024
es5-ext
medikoo
Description
The vulnerability allows a local privileged user to perform a denial of service (DoS) attack.
The vulnerability exists due to application does not properly control consumption of internal resources. A local privileged user can pass functions with very long names or complex default argument names into `function#copy` or `function#toStringTokens` and perform a denial of service (DoS) attack.