CVE-2021-27191: Uncontrolled Resource Consumption
(updated )
The get-ip-range package for Node.js is vulnerable to denial of service (DoS) if the range is untrusted input. An attacker could send a large range (such as /1
) that causes resource exhaustion.
References
Detect and mitigate CVE-2021-27191 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →