{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3asource-map-js_projectsource-map-js/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:source-map-js_project:source-map-js:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-93749"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":[],"_cs_severities":["low"],"_cs_tags":["denial-of-service","web-application","supply-chain"],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe npm package source-map-js, specifically in versions up to and including 1.2.1, contains a vulnerability related to the lack of input validation during the processing of indexed source maps. The library fails to perform proper bounds checking on the per-section offset line values provided within a source map file.\u003c/p\u003e\n\u003cp\u003eAn attacker can exploit this flaw by submitting a crafted source map containing excessively large numeric values for these offsets. When the application attempts to process this map, the lack of validation causes the Node.js event loop to block synchronously while attempting to handle the malformed data. Because Node.js is single-threaded, this blocking behavior effectively results in a denial-of-service (DoS) condition, preventing the application from processing legitimate concurrent requests. This vulnerability is particularly critical for web applications or build pipelines that process user-supplied source maps or allow dynamic parsing of such files.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a persistent denial-of-service condition for the target application by exhausting event loop resources. This impacts developers, build systems, or web applications that rely on source-map-js for parsing indexed source maps. The complexity is low as it requires only the submission of a malicious file, and no specific privileges are required, making it a viable target for automated service disruption.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for engineering teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the source-map-js dependency to a version beyond 1.2.1 as soon as a patch is available.\u003c/li\u003e\n\u003cli\u003eAudit applications utilizing source-map-js to identify instances where the parser processes untrusted or external source map input.\u003c/li\u003e\n\u003cli\u003eImplement upstream validation on all uploaded files to reject files exceeding expected size limits or containing anomalous numeric fields before reaching the parser.\u003c/li\u003e\n\u003cli\u003eMonitor application performance metrics for prolonged event loop latency or spikes in CPU usage correlated with source map processing requests.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-18T20:07:17Z","date_published":"2026-09-18T20:07:17Z","id":"https://feed.craftedsignal.io/briefs/2026-09-source-map-js-dos/","summary":"A vulnerability in source-map-js versions 1.2.1 and earlier allows unauthenticated attackers to trigger synchronous event loop blocking by supplying malformed indexed source maps containing extreme offset line values.","title":"Denial of Service via Malicious Source Maps in source-map-js","url":"https://feed.craftedsignal.io/briefs/2026-09-source-map-js-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:source-Map-Js_project:source-Map-Js:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}