Junglewise Threat Intelligence

asymmetric-effort specifyjs memory exhaustion via unrestricted data URIs

Severity: medium · CVSS 6.9 · Published 2026-07-02

Technologies: Asymmetric Effort Specifyjs, @asymmetric-effort/specifyjs (npm). Vendors: Asymmetric Effort, npm.

Executive brief

SpecifyJS, a JavaScript library, was found to process 'data:' URIs without any size limitations. An attacker could provide an extremely large data URI to exhaust the application's memory, potentially leading to a denial-of-service (DoS) condition where the service becomes unavailable to users. This issue has been resolved by implementing a 1MB limit on such URIs.

Technical details

A vulnerability exists in the `secure-fetch.ts` component of @asymmetric-effort/specifyjs where 'data:' URIs are processed without size validation. Although these URIs do not trigger external network requests, an attacker can supply a maliciously large URI to cause memory exhaustion (CWE-918/CWE-770). The attack is reachable over the network with low complexity and no prior authentication. The issue was identified during a penetration test (finding PT-005) and has been fixed in version 0.2.136 by enforcing a 1MB limit on 'data:' URIs.

Affected products

  • asymmetric-effort specifyjs < 0.2.136

Timeline

  • 2026-05-29: patched: Fixed in v0.2.136 via commit 25d1fb4
  • 2026-07-02: advisory: GitHub Advisory published

References

Related threats