Regular Expression Denial of Service in highcharts
High severity
GitHub Reviewed
Published
Mar 18, 2019
to the GitHub Advisory Database
•
Updated Apr 11, 2023
Description
Published to the GitHub Advisory Database
Mar 18, 2019
Reviewed
Jun 16, 2020
Last updated
Apr 11, 2023
Versions of
highcharts
prior to 6.1.0 are vulnerable to Regular Expression Denial of Service (ReDoS). Untrusted input may cause catastrophic backtracking while matching regular expressions. This can cause the application to be unresponsive leading to Denial of Service.Recommendation
Upgrade to version 6.1.0 or higher.
References