CVE Vulnerabilities

CVE-2024-21539

Inefficient Regular Expression Complexity

Published: Nov 19, 2024 | Modified: Apr 15, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Versions of the package @eslint/plugin-kit before 0.2.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by exploiting this vulnerability.

Weakness

The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

Potential Mitigations

References