caolan / async

Async utilities for node and the browser
http://caolan.github.io/async/
MIT License
28.15k stars 2.41k forks source link

Vulnerability in async library - CVE-2024-39249 #1988

Closed joao1498 closed 1 month ago

joao1498 commented 1 month ago

What version of async are you using? 3.2.5

Which environment did the issue occur in (Node/browser/Babel/Typescript version) Node

Hello,

Currently I detect in my application that this library are vulnerable to ReDoS (Regular Expression Denial of Service). More information can be found here: CVE-2024-39249.

Do you have any idea how and when you will solve this security related issue?

Thanks

aearly commented 1 month ago

See #1975 .