{"id":"CVE-2024-21539","details":"Versions of the package @eslint/plugin-kit before 0.2.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by exploiting this vulnerability.","aliases":["GHSA-7q7g-4xm8-89cq"],"modified":"2026-08-19T03:31:02.341330776Z","published":"2024-11-19T05:00:02.929Z","related":["CGA-vg9x-j4wf-qq58"],"database_specific":{"cwe_ids":["CWE-1333"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/21xxx/CVE-2024-21539.json","cna_assigner":"snyk"},"references":[{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-ESLINTPLUGINKIT-8340627"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/21xxx/CVE-2024-21539.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-21539"},{"type":"FIX","url":"https://github.com/eslint/rewrite/commit/071be842f0bd58de4863cdf2ab86d60f49912abf"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/eslint/rewrite","events":[{"introduced":"0"},{"fixed":"a957ee351c27ac1bf22966768cf8aac8c12ce0d2"},{"fixed":"071be842f0bd58de4863cdf2ab86d60f49912abf"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"0.2.3"}],"source":["DESCRIPTION","REFERENCES"]}}],"versions":["plugin-kit-v0.2.2","migrate-config-v1.3.3","core-v0.8.0","config-array-v0.19.0","compat-v1.2.2","plugin-kit-v0.2.1","migrate-config-v1.3.2","core-v0.7.0","compat-v1.2.1","migrate-config-v1.3.1","compat-v1.2.0","plugin-kit-v0.2.0","migrate-config-v1.3.0","core-v0.6.0","plugin-kit-v0.1.0","migrate-config-v1.2.1","core-v0.5.0","core-v0.4.0","config-array-v0.18.0","migrate-config-v1.2.0","core-v0.3.0","config-array-v0.17.1","migrate-config-v1.1.2","core-v0.2.0","compat-v1.1.1","migrate-config-v1.1.1","core-v0.1.0","config-array-v0.17.0","object-schema-v2.1.4","migrate-config-v1.1.0","config-array-v0.16.0","compat-v1.1.0","migrate-config-v1.0.1","object-schema-v2.1.3","config-array-v0.15.1","compat-v1.0.3","object-schema-v2.1.2","migrate-config-v1.0.0","config-array-v0.15.0","compat-v1.0.2","object-schema-v2.1.1","config-array-v0.14.1","compat-v1.0.1","object-schema-v2.1.0","config-array-v0.14.0","compat-v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-21539.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:P"}]}