Skip to main content
HIGH

CVE-2021-41167

CVSS v3

7.5

HIGH

EPSS Score

1.7 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

—

SSVC status

Description

modern-async is an open source JavaScript tooling library for asynchronous operations using async/await and promises. In affected versions a bug affecting two of the functions in this library: forEachSeries and forEachLimit. They should limit the concurrency of some actions but, in practice, they don't. Any code calling these functions will be written thinking they would limit the concurrency but they won't. This could lead to potential security issues in other projects. The problem has been patched in 1.0.4. There is no workaround.

Technical details

Published
2021-10-20

Frequently asked questions

What is CVE-2021-41167?

modern-async is an open source JavaScript tooling library for asynchronous operations using async/await and promises. In affected versions a bug affecting two of the functions in this library: forEachSeries and forEachLimit. They should limit the concurrency of some actions but, in practice, they don't. Any code calling these functions will be written thinking they would limit the concurrency but they won't. This could lead to potential security issues in other projects. The problem has been patched in 1.0.4. There is no workaround.

Is CVE-2021-41167 actively exploited?

Active exploitation of CVE-2021-41167 has not been confirmed. Its EPSS score was 1.7% on 2026-09-25, the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-41167?

CVE-2021-41167 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2021-41167 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key