VYPR

jsonata

by Jsonata Js

CVEs (2)

  • CVE-2026-12208MedJun 15, 2026
    risk 0.34cvss 5.3epss 0.00

    A weakness has been identified in jsonata-js jsonata up to 2.2.0. The affected element is the function createFrame of the file src/jsonata.js of the component Function Binding Frame System. This manipulation causes improperly controlled modification of object prototype…

  • CVE-2026-52746Jul 17, 2026
    risk 0.00cvss epss 0.00

    JSONata is a JSON query and transformation language. Prior to 2.2.0 and 1.8.9, malicious non-matching inputs to the $toMillis function can cause superlinear backtracking in the ISO-8601 validation regex, leading to denial of service in applications that evaluate user-provided…