Description
oswasp:
The Regular expression Denial of Service (ReDoS) is a Denial of Service attack, that exploits the fact that most Regular Expression implementations may reach extreme situations that cause them to work very slowly (exponentially related to input size).
Recommendation
Update the @highlightjs/cdn-assets package to the latest compatible version. Followings are version details:
- Affected version(s): < 10.4.1
- Patched version(s): 10.4.1
References
Related Issues
- ReDOS vulnerabities: multiple grammars - highlight.js - Vulnerability
- Marked ReDoS due to email addresses being evaluated in quadratic time - Vulnerability
- ReDoS Vulnerability in ua-parser-js version - CVE-2022-25927
- ReDoS vulnerability in vue package that is exploitable through inefficient regex evaluation in the parseHTML function - CVE-2024-9506
You might also like:
- Tags:
- npm
- @highlightjs/cdn-assets
Anything's wrong? Let us know Last updated on January 09, 2023


