VYPR
High severity7.5OSV Advisory· Published Mar 14, 2019· Updated Jun 17, 2026

CVE-2018-20801

CVE-2018-20801

Description

In js/parts/SvgRenderer.js in Highcharts JS before 6.1.0, the use of backtracking regular expressions permitted an attacker to conduct a denial of service attack against the SVGRenderer component, aka ReDoS.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
highchartsnpm
< 6.1.06.1.0

Affected products

3
  • cpe:2.3:a:highcharts:highcharts:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:highcharts:highcharts:*:*:*:*:*:*:*:*range: <6.1.0
    • (no CPE)range: highmaps-v1.0.2, highmaps-v1.1.0, highmaps-v2.1.3, …
  • ghsa-coords
    Range: < 6.1.0

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.