Vulnerability DatabaseGHSA-h96f-fc7c-9r55

GHSA-h96f-fc7c-9r55
JavaScript vulnerability analysis and mitigation

Overview

A regex denial of service (ReDoS) vulnerability was discovered in a dependency of the codesample plugin in TinyMCE, identified as GHSA-h96f-fc7c-9r55. The vulnerability was discovered by Erik Krogh Kristensen at GitHub and affects TinyMCE versions below 5.6.0. The issue was published on January 6, 2021, and has been assigned a low severity rating (GitHub Advisory).

Technical details

The vulnerability allowed poorly formed ruby code samples to lock up the browser while performing syntax highlighting. This affects users of the codesample plugin using TinyMCE 5.5.1 or lower. The issue has been classified as CWE-400 (Uncontrolled Resource Consumption) (GitHub Advisory).

Impact

When exploited, this vulnerability could cause the browser to become unresponsive while processing syntax highlighting for malformed ruby code samples, potentially leading to a denial of service condition (GitHub Advisory).

Mitigation and workarounds

Several mitigation options are available: upgrade to TinyMCE 5.6.0 or higher, disable the codesample plugin, disable ruby code samples using the codesample_languages setting, or override the PrismJS syntax highlighter to version 1.21.0 or higher using the codesample_global_prismjs setting. The vulnerability has been patched in TinyMCE 5.6.0 by upgrading to a version of the dependency without the vulnerability (Tiny Docs, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-71476HIGH8.7
  • JavaScript logoJavaScript
  • @nx/gcs-cache
NoYesAug 06, 2026
CVE-2026-71437MEDIUM6.5
  • JavaScript logoJavaScript
  • mermaid
NoYesAug 06, 2026
CVE-2026-71439MEDIUM5.3
  • JavaScript logoJavaScript
  • mermaid
NoYesAug 06, 2026
CVE-2026-71498MEDIUM5.1
  • JavaScript logoJavaScript
  • re2
NoYesAug 06, 2026
CVE-2026-71438LOW2.4
  • JavaScript logoJavaScript
  • mermaid
NoYesAug 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management