Regular Expression Denial of Service in sql-injectionGHSA-hvxq-j2r4-4jm8
GHSA-hvxq-j2r4-4jm8 is a security vulnerability in sql-injection. No vendor fix is recorded yet; mitigation options are listed below.
Real-World Exposure
sql-injectionReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects npm packages — download data is not available via public APIs for these ecosystems.
Description
All versions of sql-injection are vulnerable to Regular Expression Denial of Service. The package processes a request's body with regular expressions that may take exponentially longer to execute for large inputs.
Recommendation
No fix is currently available. Consider using an alternative package until a fix is made available.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 📦npm | sql-injection | ≥ 0.0.0 | No fix |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for sql-injection, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Remediation status
No patched version of sql-injection has shipped for GHSA-hvxq-j2r4-4jm8 yet. Where your build allows, override or pin the dependency away from the vulnerable range, and apply any maintainer-recommended mitigation.
Mitigate without a patch
Cap what an attacker can consume: apply request size, rate and timeout limits in front of the affected component, and run it with memory and CPU limits so exhaustion degrades one worker rather than the whole service.
Frequently Asked Questions
Is GHSA-hvxq-j2r4-4jm8 in your dependencies?
Find it across npm, including transitive dependencies.