VDB
RHBA-2024%3A5958
RHBA-2024%3A5958
PUBLISHED
CVSS 7.5 HIGH
A regular expression denial of service (ReDoS) flaw was found in fast-xml-parser in the currency.js script. By sending a specially crafted regex input, a remote attacker could cause a denial of service condition.
Risk Scores
CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | rhdh/rhdh-operator-bundle@sha256:5b254c0921df30ba82de1a74dacc7ed33247cbdca7ccdcbeb01c807bdf21dc0c_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9 | * |
| Red Hat | rhdh/rhdh-rhel9-operator@sha256:08e7f0f1ac066a8403cd0e04851bbcabb18802019b1e0c3d3a650397c96418a7_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9 | rhdh/rhdh-rhel9-operator@sha256:08e7f0f1ac066a8403cd0e04851bbcabb18802019b1e0c3d3a650397c96418a7_amd64 |
| Red Hat | rhdh/rhdh-hub-rhel9@sha256:4d46ad0de2834451b3e94b51dbc11083e2b167f08cefc31244347e1973eed597_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9 | rhdh/rhdh-hub-rhel9@sha256:4d46ad0de2834451b3e94b51dbc11083e2b167f08cefc31244347e1973eed597_amd64 |
Timeline
- Aug 28, 2024 CVE Published
- Apr 30, 2026 CVE Updated
- May 2, 2026 Security Advisory
- May 2, 2026 Security Advisory
References
- https://access.redhat.com/errata/RHBA-2024:5958 advisory
- https://docs.redhat.com/en/documentation/red_hat_developer_hub/1.2 advisory
- https://security.access.redhat.com/data/csaf/v2/advisories/2024/rhba-2024_5958.json advisory
- https://access.redhat.com/security/cve/CVE-2024-41818 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2300499 issue
- https://www.cve.org/CVERecord?id=CVE-2024-41818 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2024-41818 advisory
- https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/src/v5/valueParsers/currency.js#L10 advisory
- https://github.com/NaturalIntelligence/fast-xml-parser/commit/d0bfe8a3a2813a185f39591bbef222212d856164 advisory
- https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-mpg4-rc92-vx8v advisory