The Fast String Search Project maintains a specialized string-matching library with a narrow product footprint but potential for wide distribution across applications that depend on its performance-critical functionality. Its vulnerability history centers on the library's algorithmic complexity, with observed weakness classes including incorrect calculation and out-of-bounds read conditions that are characteristic of boundary-handling in optimized string-search implementations. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Fast String Search Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-22138HIGH All versions of package fast-string-search are vulnerable to Denial of Service (DoS) when computations are incorrect for non-string inputs. One can cause the V8 to attempt reading | Jun 17, 2022 | 7.5 | 25 | NO | NO |
CVE-2022-25872MEDIUM All versions of package fast-string-search are vulnerable to Out-of-bounds Read due to incorrect memory freeing and length calculation for any non-string input as the source. This | Jun 17, 2022 | 5.3 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Fast String Search Project.
Media articles that mention a CVE ID that affects a product developed by Fast String Search Project — matched by CVE ID, not by vendor name.