---
id: CVE-2024-21539
title: >-
  Versions of the package @eslint/plugin-kit before 0.2.3 are vulnerable to
  Regular Expression Denial of Service (ReDoS) due to improper input
  sanitization
summary: >-
  Versions of the package @eslint/plugin-kit before 0.2.3 are vulnerable to
  Regular Expression Denial of Service (ReDoS) due to improper input
  sanitization. An attacker can increase the CPU usage and crash the program by
  exploiting this vu…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-1333
  - CWE-770
published: '2024-11-19'
updated: '2026-08-03'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-21539'
references:
  - url: >-
      https://github.com/eslint/rewrite/commit/071be842f0bd58de4863cdf2ab86d60f49912abf
    label: report@snyk.io
  - url: 'https://security.snyk.io/vuln/SNYK-JS-ESLINTPLUGINKIT-8340627'
    label: report@snyk.io
tags:
  - nvd
epss: 0.00503
epssPercentile: 0.40434
ingestedAt: '2026-08-03T16:26:22.817Z'
---

## Overview

Versions of the package @eslint/plugin-kit before 0.2.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by exploiting this vulnerability.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
