Denial of Service Vulnerability in Source-map-js by 7rulnik
CVE-2026-93749
8.7HIGH
What is CVE-2026-93749?
The source-map-js library, up to version 1.2.1, is susceptible to a Denial of Service vulnerability due to an insufficient validation of per-section offset line values in indexed source maps. Attackers can exploit this flaw by providing exceptionally large numeric values, causing synchronous event loop blocking. This disruption prevents the service from processing other requests, significantly impacting application performance and availability.
Affected Version(s)
source-map-js 0 <= 1.2.1
