Description
The package handsontable from 0 and before 10.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) in Handsontable.helper.isNumeric
function.
Recommendation
Update the handsontable
package to the latest compatible version. Followings are version details:
- Affected version(s): < 10.0.0
- Patched version(s): 10.0.0
References
Related Issues
- Finance.js vulnerable to DoS via the seekZero() parameter - CVE-2025-56572
- Stimulsoft Dashboard.JS directory traversal vulnerability - CVE-2024-24398
- Regular Expression Denial of Service in jquery-validation - CVE-2021-21252
- jsPDF Bypass Regular Expression Denial of Service (ReDoS) - CVE-2025-29907
- Tags:
- npm
- handsontable
Anything's wrong? Let us know Last updated on September 05, 2023