CVE-2021-26272 PUBLISHED

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin).

EPSS 0.50% · 65.8th percentile

Risk Scores

EPSS Score
0.50%
65.8th percentile

Affected Products

VendorProductVersions
Ubuntu:Pro:18.04:LTSckeditor0, 4.5.7+dfsg-2, 4.5.7+dfsg-2ubuntu0.18.04.1
Ubuntu:Pro:16.04:LTSckeditor4.5.7+dfsg-2ubuntu0.16.04.1~esm3, 0, *
Ubuntu:Pro:20.04:LTSckeditor0, 4.11.1+dfsg-1, 4.12.1+dfsg-1

Timeline

References

Open in Interactive Console →