← Vulnerability Intelligence

CVE-2024-30253

Handling untrusted input can result in a crash, leading to loss of availability / denial of service

high entropyCVE-2024-30253GHSA-8m45-2rjm-j347

Entropy / wallet impact

@solana/web3.js: Using particular inputs with `@solana/web3.js` will result in memory exhaustion (OOM).

Description

Using particular inputs with @solana/web3.js will result in memory exhaustion (OOM).

If you have a server, client, mobile, or desktop product that accepts untrusted input for use with @solana/web3.js, your application/service may crash, resulting in a loss of availability.

Affected

KindNameEcosystemVersions
package@solana/web3.jsnpm>= 1.91.0, < 1.91.3

CWE

CWE-119

Primary sources

Published
2024-04-17T18:21:18Z
Last modified
2024-04-17T21:29:14Z
First seen here
2026-08-18T15:11:37Z
CVSS
7.5 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (ghsa)
Credibility
official_cve