UNKNOWN npm

Denial of Service in apostrophe

GHSA-pv6r-vchh-cxg9

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

Versions of apostrophe prior to 2.97.1 are vulnerable to Denial of Service. The apostrophe-jobs module sets a callback for incoming jobs and doesn't clear it regardless of its status. This causes the server to accumulate callbacks, allowing an attacker to start a large number of jobs and exhaust system memory.

Recommendation

Upgrade to version 2.97.1 or later.

Ready to move

Start Securing

Free, no credit card | First findings in minutes