highCVSS 7.5Vulnerability

CVE-2026-52746

### Impact In JSONata `<v2.2.0`, it is possible to craft non-matching inputs to the [$toMillis](https://docs.jsonata.org/date-time-functions#tomillis) function that cause superlinear backtracking in the ISO-8601 validation regex. This may lead to denial of service in applications that evaluate user-provided JSONata expressions. ### Patches This issue has been addressed in JSONata version >= 2.2.0 via fixes that include https://github.com/jsonata-js/jsonata/pull/782 and https://github.com/jsonata-js/jsonata/pull/793. Applications that evaluate user-provided expressions should update ASAP to prevent exploitation. ### References https://github.com/jsonata-js/jsonata/releases/tag/v2.2.0 ### Credit Thank you to Doruk Tan Öztürk for disclosing this issue.

Properties

summary
jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion
severity
high
epss_score
0.00379
cvss_score
7.5
ghsa_published
2026-07-02T20:13:55Z
source_url
https://github.com/advisories/GHSA-86vw-mfpg-wwv9
ghsa_updated
2026-07-02T20:13:56Z
ghsa_id
GHSA-86vw-mfpg-wwv9
cve_id
CVE-2026-52746
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
is_ghsa_only
false
epss_percentile
0.31056

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/jsonata

AFFECTS (1)

[Software]npm/jsonata

HAS_WEAKNESS (1)

[Weakness]Inefficient Regular Expression Complexity

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-52746 (CVSS 7.5) — Ninja Signal Threat Intelligence | Ninja Signal