Description
The express-xss-sanitizer (aka Express XSS Sanitizer) package through 2.0.0 for Node.js has an unbounded recursion depth in sanitize in lib/sanitize.js for a JSON request body.
Problem types
CWE-674 Uncontrolled Recursion
Product status
2.0.0 (semver)
References
github.com/AhmedAdelFahim/express-xss-sanitizer
www.npmjs.com/package/express-xss-sanitizer
gist.github.com/Spendroslav/177804eaef5acfb222a550de212a1b94