Denial of Service (DoS) vulnerability in RSSHub
GHSA-jvxx-v45p-v5vf · CVE-2022-31110
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Impact
Passing some special values to the filter and filterout parameters can cause an abnormally high CPU. Impact on the performance of the servers and RSSHub services.
Patches
It is fixed in 5c4177441417b44a6e45c3c63e9eac2504abeb5b , please update to this or the later versions as soon as possible.
References
Full report: https://github.com/DIYgod/RSSHub/issues/10045
For more information
If you have any questions or comments about this advisory:
- Open an issue in https://github.com/DIYgod/RSSHub/issues
- Email us at i@diygod.me
Credits
@Rongronggg9
References
- WEB https://github.com/DIYgod/RSSHub/security/advisories/GHSA-jvxx-v45p-v5vf
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2022-31110
- WEB https://github.com/DIYgod/RSSHub/issues/10045
- WEB https://github.com/DIYgod/RSSHub/commit/4671720f4c5e1aaaad8fcc1dce684b6546baf2ff
- WEB https://github.com/DIYgod/RSSHub/commit/5c4177441417b44a6e45c3c63e9eac2504abeb5b
- PACKAGE https://github.com/DIYgod/RSSHub
Ready to move
Start Securing
Free, no credit card | First findings in minutes