Executive brief
SpecifyJS, a JavaScript library, was found to process 'data:' URIs without any size limitations. An attacker could provide an extremely large data URI to exhaust the application's memory, potentially leading to a denial-of-service (DoS) condition where the service becomes unavailable to users. This issue has been resolved by implementing a 1MB limit on such URIs.
Technical details
A vulnerability exists in the `secure-fetch.ts` component of @asymmetric-effort/specifyjs where 'data:' URIs are processed without size validation. Although these URIs do not trigger external network requests, an attacker can supply a maliciously large URI to cause memory exhaustion (CWE-918/CWE-770). The attack is reachable over the network with low complexity and no prior authentication. The issue was identified during a penetration test (finding PT-005) and has been fixed in version 0.2.136 by enforcing a 1MB limit on 'data:' URIs.
Affected products
- asymmetric-effort specifyjs < 0.2.136
Timeline
- 2026-05-29: patched: Fixed in v0.2.136 via commit 25d1fb4
- 2026-07-02: advisory: GitHub Advisory published