View all vulnerabilities

CVE-2021-3801

prismjs Regular Expression Denial of Service vulnerability

Prism is a syntax highlighting library. The prismjs package is vulnerable to ReDoS (regular expression denial of service). An attacker that is able to provide a crafted HTML comment as input may cause an application to consume an excessive amount of CPU.

Patch Available

Fix available through Seal Security. No upgrade required, protect your application instantly.

Fix without upgrading
Vulnerability Details
Score
6.4
Score Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Affected Versions
prismjs < 1.25.0
Severity
Medium
Ecosystem
JavaScript
Publish Date
September 20, 2021
Modified Date
November 7, 2023