/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2024-21538

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2024-21538

Severity

Unknown

Description

Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by crafting a very large and well crafted string.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing