Description
Mathjax up to v2.7.9 was discovered to contain two Regular expression Denial of Service (ReDoS) vulnerabilities in MathJax.js via the components pattern and markdownPattern. NOTE: the vendor disputes this because the regular expressions are not applied to user input; thus, there is no risk.
Recommendation
No fix is available yet. Followings are affected versions:
- <= 2.7.9
References
Related Issues
- Switcher Client contains Regular Expression Denial of Service (ReDoS) - CVE-2023-23925
- word-wrap vulnerable to Regular Expression Denial of Service - CVE-2023-26115
- Regular Expression Denial of Service (ReDOS) - color-string - CVE-2021-29060
- tarteaucitron.js has Regular Expression Denial of Service (ReDoS) vulnerability - CVE-2026-22809
You might also like:
- Tags:
- npm
- mathjax
Anything's wrong? Let us know Last updated on January 31, 2024


