CVE-2024-21539

CVE-2024-21539CVE-2024-21539

Description

Versions of the package @eslint/plugin-kit before 0.2.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by exploiting this vulnerability.

Scoring

CVSS 7.5 ()
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Last modified2026-08-03
Sourced from NVD. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.