CVE-2026-52746

JSONata is a JSON query and transformation language. Prior to 2.2.0 and 1.8.9, malicious non-matching inputs to the $toMillis function can cause superlinear backtracking in the ISO-8601 validation regex, leading to denial of service in applications that evaluate user-provided JSONata expressions. This issue is fixed in version 2.2.0 and 1.8.9.
Configurations

Configuration 1 (hide)

cpe:2.3:a:jsonata:jsonata:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-07-17 19:17

Updated : 2026-08-03 21:16


NVD link : CVE-2026-52746

Mitre link : CVE-2026-52746

CVE.ORG link : CVE-2026-52746


JSON object : View

Products Affected

jsonata

  • jsonata
CWE
CWE-1333

Inefficient Regular Expression Complexity