Releases: yahoo/express-busboy
Releases · yahoo/express-busboy
v10.1.0
v10.0.0
v9.0.0
express-busboy@8.0.2 > connect-busboy@0.0.3 > busboy@0.3.1 > dicer@0.3.0 -- [CVE-2022-24434](https://nvd.nist.gov/vuln/detail/CVE-2022-24434) This affects all versions of package dicer.
A malicious attacker can send a modified form to server, and crash the nodejs service. An attacker could sent the payload again and again so that the service continuously crashes.