{
  "id": "security/javascript/harrisiirak__cron-parser/2026-10-06-hashed-step-expansion-heap-dos",
  "title": "cron-parser: H/<step> (and H(min-max)/<step>) field expansion is still unbounded at parse time (heap-exhaustion DoS), incomplete fix of GHSA-r9w7-75q6-r884",
  "category": "security",
  "type": "denial-of-service",
  "severity": "medium",
  "ecosystem": "javascript",
  "project": {
    "owner": "harrisiirak",
    "repo": "cron-parser",
    "url": "https://github.com/harrisiirak/cron-parser"
  },
  "affected_versions": [
    "<= 5.10.1"
  ],
  "status": "published",
  "summary": "The 256-value cap added in 5.10.1 for GHSA-r9w7-75q6-r884 runs after hashed fields are expanded, so it does not cover H/<step> or H(min-max)/<step>. Each such token expands to every value in its range before the cap applies, and a long expression of repeated tokens passed to CronExpressionParser.parse() can exhaust the Node.js heap and stop the process. Fixed in 5.10.2.",
  "discovered_at": "2026-10-06T00:00:00+03:00",
  "updated_at": "2026-10-11T18:30:00+03:00",
  "public": true,
  "credit": "ucsurf",
  "disclosure": {
    "channel": "pvr",
    "ghsa_id": "GHSA-cxfv-c5wv-5vc9",
    "cve_id": null,
    "url": "https://github.com/harrisiirak/cron-parser/security/advisories/GHSA-cxfv-c5wv-5vc9",
    "reported_at": "2026-10-09T06:21:36+03:00",
    "accepted_at": "2026-10-09T10:57:00+03:00",
    "published_at": "2026-10-11T18:06:03+03:00"
  },
  "cvss": {
    "vector": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
    "score": 5.3
  },
  "patched_versions": [
    "5.10.2"
  ],
  "pr": null
}
