CVE-2024-27088: es5-ext Regular Expression Denial of Service in `function#copy` and `function#toStringTokens`

Published Feb 26, 2024
·
Updated

Impact

Passing functions with very long names or complex default argument names into function#copy orfunction#toStringTokens may put script to stall

Patches Fixed with https://github.com/medikoo/es5-ext/commit/3551cdd7b2db08b1632841f819d008757d28e8e2 and https://github.com/medikoo/es5-ext/commit/a52e95736690ad1d465ebcd9791d54570e294602 Published with v0.10.63

Workarounds No real workaround aside of refraining from using above utilities.

References https://github.com/medikoo/es5-ext/issues/201

Other sources

es5-ext contains ECMAScript 5 extensions. Passing functions with very long names or complex default argument names into function#copy or function#toStringTokens may cause the script to stall. The vulnerability is patched in v0.10.63.

NVD

Affected Software

5 affected componentsFixes available
npm/es5-ext>=0.10.0<0.10.63
0.10.63
medikoo Es5-ext Node.js>=0.10.0<0.10.63
IBM Business Automation Insights<=25.0.0
IBM Business Automation Insights<=24.0.1
IBM Business Automation Insights<=24.0.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/es5-ext to a version that resolves this vulnerability.

    Fixed in 0.10.63
  2. Upgrade

    Upgrade medikoo/es5-ext to a version that resolves this vulnerability.

    Fixed in v0.10.63
  3. Compensating control

    Refrain from using `function#copy` and `function#toStringTokens` with functions that have very long names or complex default argument names, as passing such functions may cause the script to stall (workaround noted as “No real workaround aside of refraining from using above utilities.”).

Event History

Feb 26, 2024
CVE Published
via MITRE·04:50 PM
Data Sourced
via MITRE·04:50 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:15 PM
RemedyAffected Software
Advisory Published
via GitHub·08:01 PM
Nov 3, 2025
Data Sourced
via IBM·12:00 AM
DescriptionAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-27088?

CVE-2024-27088 has a high severity due to the potential for scripts to stall when processing long function names.

2

How do I fix CVE-2024-27088?

You can fix CVE-2024-27088 by updating the es5-ext package to version 0.10.63 or later.

3

Which versions of es5-ext are affected by CVE-2024-27088?

CVE-2024-27088 affects all versions of the es5-ext package from 0.10.0 up to 0.10.63.

4

Which IBM products are impacted by CVE-2024-27088?

IBM Planning Analytics Local - IBM Planning Analytics Workspace versions 2.0 and 2.1 are impacted by CVE-2024-27088.

5

What does CVE-2024-27088 vulnerability exploit?

CVE-2024-27088 exploits the ability of functions with long names or complex default argument names to stall scripts when processed.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203