{"id":"GHSA-86vw-mfpg-wwv9","summary":"jsonata: Malicious inputs to \"$toMillis\" function can cause resource exhaustion","details":"### Impact\nBefore JSONata `2.2.0` and `1.8.9`, it is possible to craft non-matching inputs to the [$toMillis](https://docs.jsonata.org/date-time-functions#tomillis) function that cause superlinear backtracking in the ISO-8601 validation regex. This may lead to denial of service in applications that evaluate user-provided JSONata expressions.\n\n### Patches\nThis issue has been addressed in JSONata version 2.2.0 or later, and 1.8.9 or later on v1, via fixes that include https://github.com/jsonata-js/jsonata/pull/782 and https://github.com/jsonata-js/jsonata/pull/793. Applications that evaluate user-provided expressions should update ASAP to prevent exploitation.\n\n### References\nhttps://github.com/jsonata-js/jsonata/releases/tag/v2.2.0\nhttps://github.com/jsonata-js/jsonata/releases/tag/v1.8.9\n\n### Credit\nThank you to Doruk Tan Öztürk for disclosing this issue.","aliases":["CVE-2026-52746"],"modified":"2026-08-03T21:00:22.986728376Z","published":"2026-07-02T20:13:55Z","database_specific":{"nvd_published_at":"2026-07-17T19:17:16Z","cwe_ids":["CWE-1333"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-07-02T20:13:55Z"},"references":[{"type":"WEB","url":"https://github.com/jsonata-js/jsonata/security/advisories/GHSA-86vw-mfpg-wwv9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-52746"},{"type":"WEB","url":"https://github.com/jsonata-js/jsonata/pull/782"},{"type":"WEB","url":"https://github.com/jsonata-js/jsonata/pull/793"},{"type":"WEB","url":"https://github.com/jsonata-js/jsonata/commit/80ba95d170f74e3f20f4f36b8b77d8c85cea7686"},{"type":"WEB","url":"https://github.com/jsonata-js/jsonata/commit/d6ffc17cb16a8e53c222205bd274624e919cce0b"},{"type":"PACKAGE","url":"https://github.com/jsonata-js/jsonata"},{"type":"WEB","url":"https://github.com/jsonata-js/jsonata/releases/tag/v1.8.9"},{"type":"WEB","url":"https://github.com/jsonata-js/jsonata/releases/tag/v2.2.0"}],"affected":[{"package":{"name":"jsonata","ecosystem":"npm","purl":"pkg:npm/jsonata"},"ranges":[{"type":"SEMVER","events":[{"introduced":"2.0.0"},{"fixed":"2.2.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-86vw-mfpg-wwv9/GHSA-86vw-mfpg-wwv9.json"}},{"package":{"name":"jsonata","ecosystem":"npm","purl":"pkg:npm/jsonata"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.8.9"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-86vw-mfpg-wwv9/GHSA-86vw-mfpg-wwv9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}