PT-2026-55476 · Git+2 · Jsonata

CVE-2026-52746

·

Published

2026-07-02

·

Updated

2026-07-17

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions JSONata versions prior to 2.2.0
Description Malicious non-matching inputs provided to the $toMillis() function can trigger superlinear backtracking within the ISO-8601 validation regex. This behavior can lead to a denial of service in applications that evaluate JSONata expressions provided by users.
Recommendations Update to version 2.2.0 or later.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-52746
GHSA-86VW-MFPG-WWV9

Affected Products

Jsonata