Description
source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large offset line values that cause synchronous event loop blocking for extended periods, preventing the service from handling other requests.
Published: 2026-09-18
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch Now
AI Analysis

Impact

The vulnerability is an input validation flaw in source-map-js that allows an attacker to supply arbitrary numeric values for the per-section offset line in indexed source maps. These oversized values cause the library to execute synchronously for extended periods, blocking the event loop and preventing the application from handling other requests. The weakness is classified as CWE-1284 and CWE-1285, both involving improper validation of numeric input.

Affected Systems

Affected vendor "7rulnik" and its product "source-map-js". Versions through and including 1.2.1 are impacted.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity impact, and the EPSS score of less than 1% suggests the likelihood of exploitation is currently very low. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack vector is inferred to involve an attacker who can supply a crafted source map file that is processed by the library, such as through a malicious dependency upload or an untrusted source map used in an application. The denial of service manifests as a prolonged synchronous event loop block, which may affect multiple concurrent users while the processing occurs.

Generated by OpenCVE AI on September 23, 2026 at 01:39 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade source-map-js to a release that includes the offset line validation fix.
  • Add a pre-processing check that validates any offset line values to be within a reasonable range before passing them to source-map-js.
  • Limit the use of source-map-js to trusted source maps only, or sandbox the parsing so that a denial of service in the library does not impact the entire application.

Generated by OpenCVE AI on September 23, 2026 at 01:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-68fv-2mgg-jv7q source-map-js allows event-loop denial of service through indexed source-map section offsets
History

Thu, 24 Sep 2026 04:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 00:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-1285
References
Metrics threat_severity

None

threat_severity

Important


Mon, 21 Sep 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared 7rulnik
7rulnik source-map-js
Vendors & Products 7rulnik
7rulnik source-map-js

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description source-map-js through 1.2.1 fails to validate the per-section offset line value in indexed source maps, allowing attackers to specify arbitrary numeric values. Attackers can supply extremely large offset line values that cause synchronous event loop blocking for extended periods, preventing the service from handling other requests.
Title source-map-js through 1.2.1 Event Loop Denial of Service
Weaknesses CWE-1284
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

7rulnik Source-map-js
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-24T14:23:08.247Z

Reserved: 2026-09-18T16:30:17.433Z

Link: CVE-2026-93749

cve-icon Vulnrichment

Updated: 2026-09-22T15:16:55.106Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-18T18:18:33.480

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-93749

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-18T17:51:34Z

Links: CVE-2026-93749 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T01:45:19Z

Weaknesses
  • CWE-1284

    Improper Validation of Specified Quantity in Input

  • CWE-1285

    Improper Validation of Specified Index, Position, or Offset in Input