Skip to content

Highlight.js DOS issue

Low
evert published GHSA-j7mc-fjmh-w8f9 Dec 4, 2020

Package

npm a12nserver (npm)

Affected versions

< 0.14.1

Patched versions

0.14.1

Description

Issue in a dependency of a12n-server:
https://github.com/highlightjs/highlight.js/releases
Impact is likely low due to highlight.js only really being used for JSON.

Users of the a12nserver package will get the updated dependency anyway, so this security issue only affects users of the pre-built docker image.

Severity

Low

CVE ID

No known CVE

Weaknesses

No CWEs