PT-2026-55476 · Git+2 · Jsonata
CVE-2026-52746
·
Published
2026-07-02
·
Updated
2026-07-17
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
JSONata versions prior to 2.2.0
Description
Malicious non-matching inputs provided to the
$toMillis() function can trigger superlinear backtracking within the ISO-8601 validation regex. This behavior can lead to a denial of service in applications that evaluate JSONata expressions provided by users.Recommendations
Update to version 2.2.0 or later.
Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jsonata