HIGH7.5
GHSA-v638-q856-grg8
MathJax Regular expression Denial of Service (ReDoS)
Details
Mathjax up to v2.7.9 was discovered to contain two Regular expression Denial of Service (ReDoS) vulnerabilities in MathJax.js via the components pattern and markdownPattern. NOTE: the vendor disputes this because the regular expressions are not applied to user input; thus, there is no risk.
Are you affected?
Enter the version of the package you're using.
Affected packages
npm/mathjax
Introduced in:
0No fixed version published yet for mathjax (npm). Pin to a known-safe version or switch to an alternative.