All vulnerabilities
CVE-2021-3801
prismjs Regular Expression Denial of Service vulnerability
Description
Prism is a syntax highlighting library. The prismjs package is vulnerable to ReDoS (regular expression denial of service). An attacker that is able to provide a crafted HTML comment as input may cause an application to consume an excessive amount of CPU.
Patch Available
Fix available through Seal Security.
No upgrade required, protect your application instantly.
Fix without upgrading
Score
Severity
Ecosystem
JavaScript
Publish Date
September 20, 2021
Modified Date
November 7, 2023
Score Vector
Affected Versions

