GHSA-3rh3-wfr4-76mj

    Dashboard / Vulnerabilities / GHSA-3rh3-wfr4-76mj

    GHSA-3rh3-wfr4-76mj

    Published: 6 Apr 2021Last Modified: 8 Jul 2026

    Summary: Regular expression Denial of Service in multiple packages

    Details: ### Impact A regular expression denial of service (ReDoS) vulnerability has been discovered in multiple CKEditor 5 packages. The vulnerability allowed to abuse particular regular expressions, which could cause a significant performance drop resulting in a browser tab freeze. It affects all users using the CKEditor 5 packages listed above at version <= 26.0.0. ### Patches The problem has been recognized and patched. The fix will be available in version 27.0.0. ### For more information Email us at [email protected] if you have any questions or comments about this advisory. ### Acknowledgements The CKEditor 5 team would like to thank Yeting Li for recognizing and reporting these vulnerabilities.

    Affected packages

    Package

    Name: @ckeditor/ckeditor5-engine

    Purl: pkg:npm/%40ckeditor/ckeditor5-engine

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -27.0.0

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-3rh3-wfr4-76mj | CVE-DB