Skip to content
LowVulnerability

GHSA-866g-f22w-33x8: @ai-sdk/provider-utils has an Uncontrolled Resource Consumption issue

Published
Record updated
View JSON
Affected
  • @ai-sdk/provider-utils < 3.0.28, fixed in 3.0.28
  • @ai-sdk/provider-utils >= 4.0.0-beta.10, < 4.0.33, fixed in 4.0.33
  • @ai-sdk/provider-utils >= 5.0.0-beta.0, < 5.0.1, fixed in 5.0.1
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.7%

Summary

Versions of `@ai-sdk/provider-utils` before 3.0.28, from 4.0.0 before 4.0.33, and from 5.0.0 before 5.0.1 are vulnerable to uncontrolled resource consumption. The functions `createJsonResponseHandler`, `createJsonErrorResponseHandler`, and `createStatusCodeErrorResponseHandler` in `packages/provider-utils/src/response-handler.ts` read response bodies without a shared size limit, so a remote attacker with low privileges can cause excessive memory consumption. A public exploit has been disclosed.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.