Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
7.5
CVE-2026-52746
- EPSS 0.38%
- Veröffentlicht 17.07.2026 18:32:47
- Zuletzt bearbeitet 03.08.2026 21:16:40
JSONata is a JSON query and transformation language. Prior to 2.2.0 and 1.8.9, malicious non-matching inputs to the $toMillis function can cause superlinear backtracking in the ISO-8601 validation regex, leading to denial of service in applications t...
9.8
CVE-2024-27307
- EPSS 1.42%
- Veröffentlicht 06.03.2024 20:15:47
- Zuletzt bearbeitet 04.12.2025 17:55:46
JSONata is a JSON query and transformation language. Starting in version 1.4.0 and prior to version 1.8.7 and 2.0.4, a malicious expression can use the transform operator to override properties on the `Object` constructor and prototype. This may lead...
1