Executive brief
json-bigint is a JavaScript library that parses JSON with support for arbitrary-precision integers. A prototype pollution vulnerability allows an attacker to craft malicious JSON input that causes uncontrolled memory consumption, leading to application crashes or service unavailability without authentication.
Technical details
The vulnerability is a prototype pollution flaw (CWE-400: Uncontrolled Resource Consumption) in json-bigint versions prior to 1.0.0. An attacker can craft specially formatted JSON input that pollutes the JavaScript object prototype, triggering excessive resource consumption and denial of service. The attack is network-accessible with no authentication or user interaction required, though exploitation typically requires the attacker to provide the malicious JSON payload to the application. The vulnerability was fixed in version 1.0.0.
Affected products
- json-bigint json-bigint < 1.0.0
Timeline
- 2021-05-07: disclosed
- 2021-05-07: patched: Fixed in version 1.0.0