Description
oswasp:
The Regular expression Denial of Service (ReDoS) is a Denial of Service attack, that exploits the fact that most Regular Expression implementations may reach extreme situations that cause them to work very slowly (exponentially related to input size).
Recommendation
Update the highlight.js package to the latest compatible version. Followings are version details:
- Affected version(s): >= 9.0.0, < 10.4.1
- Patched version(s): 10.4.1
References
Could your website be exposed too?
SmartScanner can check your website for ReDOS vulnerabities: multiple grammars - highlight.js and gives you actionable findings to investigate.
Start a free scanRelated Issues
- ReDOS vulnerabities: multiple grammars - Vulnerability
- ReDoS Vulnerability in ua-parser-js version - CVE-2022-25927
- string-math's string-math.js vulnerability can cause Regex Denial of Service (ReDoS) - CVE-2025-45143
- d3-color vulnerable to ReDoS - Vulnerability


