MEDIUM 5.3 npm

Denial of Service (DoS) vulnerability in RSSHub

GHSA-jvxx-v45p-v5vf · CVE-2022-31110

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Impact

Passing some special values to the filter and filterout parameters can cause an abnormally high CPU. Impact on the performance of the servers and RSSHub services.

Patches

It is fixed in 5c4177441417b44a6e45c3c63e9eac2504abeb5b , please update to this or the later versions as soon as possible.

References

Full report: https://github.com/DIYgod/RSSHub/issues/10045

For more information

If you have any questions or comments about this advisory:

Credits

@Rongronggg9

Ready to move

Start Securing

Free, no credit card | First findings in minutes