Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-29138 | express-xss-sanitizer has an unbounded recursion depth |
Github GHSA |
GHSA-hvq2-wf92-j4f3 | express-xss-sanitizer has an unbounded recursion depth |
Mon, 15 Sep 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 15 Sep 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Express Xss Sanitizer Project
Express Xss Sanitizer Project express Xss Sanitizer |
|
| Vendors & Products |
Express Xss Sanitizer Project
Express Xss Sanitizer Project express Xss Sanitizer |
Sun, 14 Sep 2025 22:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The express-xss-sanitizer (aka Express XSS Sanitizer) package through 2.0.0 for Node.js has an unbounded recursion depth in sanitize in lib/sanitize.js for a JSON request body. | |
| Weaknesses | CWE-674 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2025-09-15T15:57:53.693Z
Reserved: 2025-09-14T00:00:00.000Z
Link: CVE-2025-59364
Updated: 2025-09-15T15:57:50.972Z
Status : Deferred
Published: 2025-09-14T23:15:37.320
Modified: 2026-04-15T00:35:42.020
Link: CVE-2025-59364
No data.
OpenCVE Enrichment
Updated: 2025-09-15T10:43:26Z
EUVD
Github GHSA