VDB

RHBA-2024%3A5958

RHBA-2024%3A5958 PUBLISHED CVSS 7.5 HIGH

A regular expression denial of service (ReDoS) flaw was found in fast-xml-parser in the currency.js script. By sending a specially crafted regex input, a remote attacker could cause a denial of service condition.

Risk Scores

CVSS 3.1
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected Products

VendorProductVersions
Red Hatrhdh/rhdh-operator-bundle@sha256:5b254c0921df30ba82de1a74dacc7ed33247cbdca7ccdcbeb01c807bdf21dc0c_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9*
Red Hatrhdh/rhdh-rhel9-operator@sha256:08e7f0f1ac066a8403cd0e04851bbcabb18802019b1e0c3d3a650397c96418a7_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9rhdh/rhdh-rhel9-operator@sha256:08e7f0f1ac066a8403cd0e04851bbcabb18802019b1e0c3d3a650397c96418a7_amd64
Red Hatrhdh/rhdh-hub-rhel9@sha256:4d46ad0de2834451b3e94b51dbc11083e2b167f08cefc31244347e1973eed597_amd64 as a component of Red Hat Developer Hub 1.2 for RHEL 9rhdh/rhdh-hub-rhel9@sha256:4d46ad0de2834451b3e94b51dbc11083e2b167f08cefc31244347e1973eed597_amd64

Timeline

  • Aug 28, 2024 CVE Published
  • Apr 30, 2026 CVE Updated
  • May 2, 2026 Security Advisory
  • May 2, 2026 Security Advisory
Open in Interactive Console →
$ Console Community · 100/wk Open console ›