GHSA-86vw-mfpg-wwv9

Suggest an improvement
Source
https://github.com/advisories/GHSA-86vw-mfpg-wwv9
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-86vw-mfpg-wwv9/GHSA-86vw-mfpg-wwv9.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-86vw-mfpg-wwv9
Aliases
Downstream
Published
2026-07-02T20:13:55Z
Modified
2026-08-03T21:00:22Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion
Details

Impact

Before JSONata 2.2.0 and 1.8.9, it is possible to craft non-matching inputs to the $toMillis function that cause superlinear backtracking in the ISO-8601 validation regex. This may lead to denial of service in applications that evaluate user-provided JSONata expressions.

Patches

This issue has been addressed in JSONata version 2.2.0 or later, and 1.8.9 or later on v1, via fixes that include https://github.com/jsonata-js/jsonata/pull/782 and https://github.com/jsonata-js/jsonata/pull/793. Applications that evaluate user-provided expressions should update ASAP to prevent exploitation.

References

https://github.com/jsonata-js/jsonata/releases/tag/v2.2.0 https://github.com/jsonata-js/jsonata/releases/tag/v1.8.9

Credit

Thank you to Doruk Tan Öztürk for disclosing this issue.

Database specific
{
    "cwe_ids": [
        "CWE-1333"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-07-02T20:13:55Z",
    "nvd_published_at": "2026-07-17T19:17:16Z",
    "severity": "HIGH"
}
References

Affected packages

npm / jsonata

Package

Affected ranges

Type
SEMVER
Events
Introduced
2.0.0
Fixed
2.2.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-86vw-mfpg-wwv9/GHSA-86vw-mfpg-wwv9.json"

npm / jsonata

Package

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.8.9

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-86vw-mfpg-wwv9/GHSA-86vw-mfpg-wwv9.json"