Vulnerability GHSA-hp3w-g68c-fv3c
Medium Risk
MEDIUM RISK
CVSS Score: 5.3
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
11 days ago
September 24, 2026 at 03:31 PM UTC
sprintf-js vulnerable to denial of service through unbounded precision specifiers
0.0.7 - 1.1.3
0.0.7 - 1.1.3
Summary
sprintf-js vulnerable to denial of service through unbounded precision specifiers
Details
sprintf-js through 1.1.3 passes unbounded precision specifiers to toFixed, toExponential, and toPrecision methods without validation, causing uncaught RangeError exceptions. Attackers who control format strings can inject precision values exceeding ECMAScript limits to abort calling operations with minimal payload.
Impacted packages
Timeline
Published
11 days ago
September 24, 2026 at 03:31 PM UTC
Last Modified
7 hours ago
October 06, 2026 at 12:00 AM UTC