Skip to content

next vulnerability in getsentry/sentry-javascript #18645

@Jeffreyhung

Description

@Jeffreyhung

Reachability: Always Reachable

Vulnerable code in yarn.lock:23093

Affected versions of next are vulnerable to Dependency on Vulnerable Third-Party Component / Deserialization of Untrusted Data / Uncontrolled Resource Consumption. An attacker can send a specially crafted HTTP request to any Server Function endpoint (as used by Next.js' App Router) that, when deserialized by the React Server Components runtime, enters an infinite loop—hanging the server process, exhausting CPU, and resulting in a denial-of-service.

Severity: High

Current version: 13.5.9

Recommended fix version: 14.2.35

References:

Metadata

Metadata

Assignees

No one assigned

    Labels

    javascriptPull requests that update javascript code

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions