{"id":"CVE-2024-27088","aliases":["GHSA-4gmj-3p3h-gm8h"],"url":"https://o3.security/vulnerability/CVE-2024-27088","summary":"es5-ext Regular Expression Denial of Service in `function#copy` and `function#toStringTokens`","details":"### Impact\n\nPassing functions with very long names or complex default argument names into `function#copy` or`function#toStringTokens` may put script to stall\n\n### Patches\nFixed with https://github.com/medikoo/es5-ext/commit/3551cdd7b2db08b1632841f819d008757d28e8e2 and https://github.com/medikoo/es5-ext/commit/a52e95736690ad1d465ebcd9791d54570e294602\nPublished with v0.10.63\n\n### Workarounds\nNo real workaround aside of refraining from using above utilities.\n\n### References\nhttps://github.com/medikoo/es5-ext/issues/201\n","published":"2024-02-26T16:50:05.714Z","modified":"2026-08-12T03:51:44.747327557Z","cvss":{"score":0,"severity":"NONE","vector":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"es5-ext","fixedVersion":"0.10.63"}],"fix":{"url":"https://github.com/medikoo/es5-ext/commit/3551cdd7b2db08b1632841f819d008757d28e8e2","label":"medikoo/es5-ext@3551cdd"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/27xxx/CVE-2024-27088.json"},{"type":"ADVISORY","url":"https://github.com/medikoo/es5-ext/security/advisories/GHSA-4gmj-3p3h-gm8h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-27088"},{"type":"REPORT","url":"https://github.com/medikoo/es5-ext/issues/201"},{"type":"FIX","url":"https://github.com/medikoo/es5-ext/commit/3551cdd7b2db08b1632841f819d008757d28e8e2"},{"type":"FIX","url":"https://github.com/medikoo/es5-ext/commit/a52e95736690ad1d465ebcd9791d54570e294602"},{"type":"PACKAGE","url":"https://github.com/medikoo/es5-ext"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:44.747327557Z"}}