Junglewise Threat Intelligence

@asymmetric-effort/specifyjs unrestricted data URI memory exhaustion

Severity: medium · CVSS 4 · Published 2026-07-02

Technologies: Asymmetric Effort Specifyjs, @asymmetric-effort/specifyjs (npm). Vendors: Asymmetric Effort, npm.

Executive brief

SpecifyJS is a TypeScript UI framework that includes a secure-fetch module for handling network requests. An attacker can cause memory exhaustion and application crash by submitting extremely large data: URIs without size restrictions. This can be exploited to disable the application or degrade performance for legitimate users. The fix in v0.2.136 enforces a 1MB limit on data: URIs and throws an error for oversized URIs.

Technical details

The vulnerability exists in core/src/shared/secure-fetch.ts (lines 33-35) where data: URIs are accepted without any size validation. While data: URIs do not trigger outbound network requests (mitigating traditional SSRF concerns), they can be exploited for memory exhaustion attacks when arbitrarily large payloads are embedded. The attack vector is network-based with no authentication required. An attacker can craft requests with massive data: URIs to exhaust the server or client's available memory, causing denial of service. The vulnerability is classified under CWE-918 (Server-Side Request Forgery) due to the URI handling context. A patch was released in v0.2.136 that enforces a 1MB maximum size limit and throws an error when the limit is exceeded.

Affected products

  • @asymmetric-effort specifyjs < 0.2.136

Timeline

  • 2026-05-29: disclosed: Vulnerability discovered during penetration testing
  • 2026-05-29: patched: Fixed in v0.2.136 with 1MB data: URI size limit
  • 2026-07-02: advisory: GHSA-2944-57xv-2682 published

References

Related threats