GHSA-HVQ2-WF92-J4F3

Vulnerability from github – Published: 2025-09-26 14:38 – Updated: 2025-09-26 14:38
VLAI
Summary
express-xss-sanitizer has an unbounded recursion depth
Details

Security Advisory: express-xss-sanitizer

Overview

A vulnerability was discovered in express-xss-sanitizer that allowed unbounded recursion depth during sanitization of nested objects.

Affected Versions

  • All versions prior to 2.0.1

Patched Versions

  • 2.0.1 and later

Description

The sanitize function in lib/sanitize.js performed recursive sanitization without depth limiting, making it vulnerable to stack overflow attacks via specially crafted deeply nested JSON objects.

Impact

An attacker could cause denial-of-service by sending a request with deeply nested structures, potentially crashing the Node.js process.

Solution

Upgrade to version 2.0.1 or later:

npm install express-xss-sanitizer@latest
Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "express-xss-sanitizer"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2.0.1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2025-59364"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-674"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2025-09-26T14:38:13Z",
    "nvd_published_at": null,
    "severity": "MODERATE"
  },
  "details": "# Security Advisory: express-xss-sanitizer\n\n## Overview\nA vulnerability was discovered in express-xss-sanitizer that allowed unbounded recursion depth during sanitization of nested objects.\n\n## Affected Versions\n- All versions prior to 2.0.1\n\n## Patched Versions\n- 2.0.1 and later\n\n## Description\nThe sanitize function in lib/sanitize.js performed recursive sanitization without depth limiting, making it vulnerable to stack overflow attacks via specially crafted deeply nested JSON objects.\n\n## Impact\nAn attacker could cause denial-of-service by sending a request with deeply nested structures, potentially crashing the Node.js process.\n\n## Solution\nUpgrade to version 2.0.1 or later:\n\n```bash\nnpm install express-xss-sanitizer@latest\n```",
  "id": "GHSA-hvq2-wf92-j4f3",
  "modified": "2025-09-26T14:38:14Z",
  "published": "2025-09-26T14:38:13Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/AhmedAdelFahim/express-xss-sanitizer/security/advisories/GHSA-hvq2-wf92-j4f3"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-59364"
    },
    {
      "type": "WEB",
      "url": "https://github.com/AhmedAdelFahim/express-xss-sanitizer/pull/23"
    },
    {
      "type": "WEB",
      "url": "https://github.com/AhmedAdelFahim/express-xss-sanitizer/commit/62d6542a2a57298da7a2e02de623454007e4f6d6"
    },
    {
      "type": "WEB",
      "url": "https://dbugs.ptsecurity.com/vulnerability/PT-2025-37434"
    },
    {
      "type": "WEB",
      "url": "https://gist.github.com/Spendroslav/177804eaef5acfb222a550de212a1b94"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/AhmedAdelFahim/express-xss-sanitizer"
    },
    {
      "type": "WEB",
      "url": "https://www.npmjs.com/package/express-xss-sanitizer"
    },
    {
      "type": "WEB",
      "url": "https://www.tenable.com/cve/CVE-2025-59364"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "express-xss-sanitizer has an unbounded recursion depth"
}



Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Forecast uses a logistic model when the trend is rising, or an exponential decay model when the trend is falling. Fitted via linearized least squares.

Sightings

Author Source Type Date Other

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or observed by the user.
  • Confirmed: The vulnerability has been validated from an analyst's perspective.
  • Published Proof of Concept: A public proof of concept is available for this vulnerability.
  • Exploited: The vulnerability was observed as exploited by the user who reported the sighting.
  • Patched: The vulnerability was observed as successfully patched by the user who reported the sighting.
  • Not exploited: The vulnerability was not observed as exploited by the user who reported the sighting.
  • Not confirmed: The user expressed doubt about the validity of the vulnerability.
  • Not patched: The vulnerability was not observed as successfully patched by the user who reported the sighting.

Loading…

Loading…

Loading…

Related by attack behaviour

Vulnerabilities whose description is nearest to this one in the vector space of the CIRCL/vulnerability-attack-technique-biencoder model. This is a similarity search over the bi-encoder space (plain cosine), not a classification, and it has no measured accuracy.


Loading…