CVE-2019-20922
Regular Expression Denial of Service in Handlebars
7.5
HIGH
CVSS 3.1
EPSS 0.29%
Description
Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templates. This may allow attackers to exhaust system resources.
How to fix CVE-2019-20922
To remediate CVE-2019-20922, upgrade the affected package to a fixed version below.
- —upgrade to 4.4.5 or later
Is CVE-2019-20922 being exploited?
Low — EPSS is 0.3%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- >= 4.0.0, < 4.4.5
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |