High severity7.5NVD Advisory· Published Sep 30, 2020· Updated Jun 17, 2026
CVE-2019-20922
CVE-2019-20922
Description
Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templates. This may allow attackers to exhaust system resources.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
handlebarsnpm | >= 4.0.0, < 4.4.5 | 4.4.5 |
Affected products
3- Handlebars/Handlebarsdescription
Patches
Vulnerability mechanics
References
6- github.com/handlebars-lang/handlebars.js/commit/8d5530ee2c3ea9f0aee3fde310b9f36887d00b8bnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-62gr-4qp9-h98fghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-20922ghsaADVISORY
- snyk.io/vuln/SNYK-JS-HANDLEBARS-480388nvdThird Party AdvisoryWEB
- www.npmjs.com/advisories/1300nvdThird Party AdvisoryWEB
- www.npmjs.com/package/handlebarsghsaWEB
News mentions
0No linked articles in our index yet.