VDB
Sign up
HIGH7.5

GHSA-xmc8-cjfr-phx3

Regular Expression Denial of Service in highcharts

Quick fix

GHSA-xmc8-cjfr-phx3 — highcharts: upgrade to the fixed version with the command below.

npm install highcharts@6.1.0

Details

Versions of `highcharts` prior to 6.1.0 are vulnerable to Regular Expression Denial of Service (ReDoS). Untrusted input may cause catastrophic backtracking while matching regular expressions. This can cause the application to be unresponsive leading to Denial of Service.

## Recommendation

Upgrade to version 6.1.0 or higher.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/highcharts
Introduced in: 0Fixed in: 6.1.0
Fixnpm install highcharts@6.1.0

References