CVE-2026-52746
### Impact In JSONata `<v2.2.0`, it is possible to craft non-matching inputs to the [$toMillis](https://docs.jsonata.org/date-time-functions#tomillis) function that cause superlinear backtracking in the ISO-8601 validation regex. This may lead to denial of service in applications that evaluate user-provided JSONata expressions. ### Patches This issue has been addressed in JSONata version >= 2.2.0 via fixes that include https://github.com/jsonata-js/jsonata/pull/782 and https://github.com/jsonata-js/jsonata/pull/793. Applications that evaluate user-provided expressions should update ASAP to prevent exploitation. ### References https://github.com/jsonata-js/jsonata/releases/tag/v2.2.0 ### Credit Thank you to Doruk Tan Öztürk for disclosing this issue.
Properties
- summary
- jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion
- severity
- high
- epss_score
- 0.00379
- cvss_score
- 7.5
- ghsa_published
- 2026-07-02T20:13:55Z
- source_url
- https://github.com/advisories/GHSA-86vw-mfpg-wwv9
- ghsa_updated
- 2026-07-02T20:13:56Z
- ghsa_id
- GHSA-86vw-mfpg-wwv9
- cve_id
- CVE-2026-52746
- cvss_vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- is_ghsa_only
- false
- epss_percentile
- 0.31056
Related Entities (5)
ENRICHED_BY (1)
REPORTED_BY (1)
VULNERABLE_TO (1)
AFFECTS (1)
HAS_WEAKNESS (1)
Explore deeper with Ninja Signal's threat intelligence graph