CVE-2024-39249: Async Project Async
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
Async <= 2.6.4 and <= 3.2.5 are vulnerable to ReDoS (Regular Expression Denial of Service) while parsing function in autoinject function. NOTE: this is disputed by the supplier because there is no realistic threat model: regular expressions are not used with untrusted input.
Affected products
- Async Project Async: up to and including 2.6.4; up to and including 3.2.5
Published 2024-07-01. Last modified 2026-06-17.