nodejs / nodejs/nodejs-dependency-vuln-assessments

jsdiff has a Denial of Service vulnerability in parsePatch and applyPatch

Open
#223 6 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

dont-believe-affects-nodejs
Dominant language
Python
Stars
22
Forks
7
PR merge metrics
No merged PRs in 30d

Description

Version

v22.19.0

Platform

Subsystem

No response

What steps will reproduce the bug?

It seems NodeJS v22.19.0 includes vulnerability
/usr/lib/node_modules/npm/node_modules/diff

https://github.com/advisories/GHSA-73rr-hh4g-fpgx

How often does it reproduce? Is there a required condition?

Scanner

What is the expected behavior? Why is that the expected behavior?

No security

What do you see instead?
Additional information

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reading the linked GHSA advisory and checking the reported Node.js npm dependency path for the affected jsdiff version. The issue provides no reproduction or repository file to change, so done would require confirming the vulnerability's relevance and identifying the repository's required remediation or assessment outcome.

Written by the indexing model from the issue text.

Assessment

Tech stack
javascript, node.js
Domain
security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.