Junglewise Threat Intelligence

CVE-2021-29057: SUCHMOKUO node-worker-threads-pool denial of service

CVE-2021-29057 · Severity: low · CVSS 3.1 · Published 2023-08-11

Vendors: npm.

Executive brief

node-worker-threads-pool is a Node.js library for managing worker thread pools. A denial of service vulnerability allows attackers to submit tasks with infinite loops that freeze worker threads indefinitely, causing the thread pool to become exhausted and unable to process subsequent tasks. This can crash or hang applications relying on this library for concurrent task execution.

Technical details

The vulnerability exists in the StaticPool component, where tasks can hang indefinitely (e.g., via infinite loops or expensive computations). When a task exceeds its timeout, the worker thread is not properly terminated or recovered; instead, it remains hijacked. An attacker can submit malicious tasks designed to exhaust all available workers, causing the pool to reject or stall subsequent legitimate requests. The vulnerability is rooted in improper timeout handling and lack of notification to the application when a task timeout occurs (CWE-400: Uncontrolled Resource Consumption, CWE-770: Allocation of Resources Without Limits or Throttling). No authentication is required; any code instantiating the pool can trigger the issue. Patches or workarounds have not been definitively documented in the advisory.

Affected products

  • SUCHMOKUO node-worker-threads-pool 0 to 1.4.3

Timeline

  • 2021-03-19: disclosed: Issue reported on GitHub
  • 2023-08-11: advisory: GHSA-7vxc-q7rv-qfj8 published

References