Vulnerability GHSA-68fv-2mgg-jv7q
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
17 days ago
September 18, 2026 at 06:31 PM UTC
source-map-js allows event-loop denial of service through indexed source-map section offsets
1.0.0 - 1.2.1
1.0.0 - 1.2.1
Summary
source-map-js allows event-loop denial of service through indexed source-map section offsets
Details
source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large offset line values that cause synchronous event loop blocking for extended periods, preventing the service from handling other requests.
Impacted packages
Timeline
Published
17 days ago
September 18, 2026 at 06:31 PM UTC
Fixed (1.2.2)
Unknown
Unknown
Last Modified
7 hours ago
October 05, 2026 at 11:45 PM UTC