---
id: CVE-2021-26271
title: >-
  It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16
  by persuading a victim to paste crafted text into the Styles input of specific
  dialogs (in the Advanced Tab for Dialogs plugin).
summary: >-
  It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16
  by persuading a victim to paste crafted text into the Styles input of specific
  dialogs (in the Advanced Tab for Dialogs plugin).
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'
cwe:
  - CWE-829
vendor: ckeditor
product: ckeditor
affected:
  - 'ckeditor >= 4.0, < 4.16'
  - agile_product_lifecycle_management = 9.3.5
  - agile_product_lifecycle_management = 9.3.6
  - application_express < 21.1.0
  - 'financial_services_analytical_applications_infrastructure >= 8.0.6, <= 8.0.9'
  - financial_services_analytical_applications_infrastructure = 8.1.0
  - financial_services_analytical_applications_infrastructure = 8.1.1
  - jd_edwards_enterpriseone_tools < 9.2.6.0
  - siebel_ui_framework < 21.9
  - webcenter_sites = 12.2.1.3.0
  - webcenter_sites = 12.2.1.4.0
patched:
  - ckeditor 4.16
  - application_express 21.1.0
  - jd_edwards_enterpriseone_tools 9.2.6.0
  - siebel_ui_framework 21.9
published: '2021-01-26'
updated: '2026-08-25'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-26271'
references:
  - url: >-
      https://ckeditor.com/blog/CKEditor-4.16-with-improved-image-pasting-High-Contrast-support-and-a-new-color-API/#security-comes-first
    label: cve@mitre.org
  - url: 'https://github.com/ckeditor/ckeditor4/blob/major/CHANGES.md#ckeditor-416'
    label: cve@mitre.org
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: cve@mitre.org
  - url: >-
      https://ckeditor.com/blog/CKEditor-4.16-with-improved-image-pasting-High-Contrast-support-and-a-new-color-API/#security-comes-first
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://github.com/ckeditor/ckeditor4/blob/major/CHANGES.md#ckeditor-416'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.0197
epssPercentile: 0.79527
ingestedAt: '2026-08-25T17:29:31.056Z'
---

## Overview

It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).

## Affected

- `ckeditor >= 4.0, < 4.16`
- `agile_product_lifecycle_management = 9.3.5`
- `agile_product_lifecycle_management = 9.3.6`
- `application_express < 21.1.0`
- `financial_services_analytical_applications_infrastructure >= 8.0.6, <= 8.0.9`
- `financial_services_analytical_applications_infrastructure = 8.1.0`
- `financial_services_analytical_applications_infrastructure = 8.1.1`
- `jd_edwards_enterpriseone_tools < 9.2.6.0`
- `siebel_ui_framework < 21.9`
- `webcenter_sites = 12.2.1.3.0`
- `webcenter_sites = 12.2.1.4.0`

## Remediation

Upgrade past the affected range:

- `ckeditor 4.16`
- `application_express 21.1.0`
- `jd_edwards_enterpriseone_tools 9.2.6.0`
- `siebel_ui_framework 21.9`
