CVE-2024-30253: @solana/web3.js vulnerable to Denial of Service attack via Message/Transaction object deserialization
Using particular inputs with @solana/web3.js
will result in memory exhaustion (OOM).
If you have a server, client, mobile, or desktop product that accepts untrusted input for use with @solana/web3.js
, your application/service may crash, resulting in a loss of availability.
References
Detect and mitigate CVE-2024-30253 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →