Vulnerabilities/

jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion

Severity:
High

Description

Before JSONata 2.2.0 and 1.8.9, it is possible to craft non-matching inputs to the $toMillis function that cause superlinear backtracking in the ISO-8601 validation regex. This may lead to denial of service in applications that evaluate user-provided JSONata expressions.

Recommendation

Update the jsonata package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
jsonata
Anything's wrong? Let us know Last updated on August 03, 2026