Description
The package handsontable from 0 and before 10.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) in Handsontable.helper.isNumeric function.
Recommendation
Update the handsontable package to the latest compatible version. Followings are version details:
- Affected version(s): < 10.0.0
- Patched version(s): 10.0.0
References
Related Issues
- html2pdf.js contains a cross-site scripting vulnerability - CVE-2026-22787
- Altcha Proof-of-Work obfuscation mode cryptanalytic break - CVE-2025-65849
- fastify-reply-from affected by bypass of reply forwarding - CVE-2025-66415
- Finance.js vulnerable to DoS via the seekZero() parameter - CVE-2025-56572
- Tags:
- npm
- handsontable
Anything's wrong? Let us know Last updated on September 05, 2023