CVE-2026-52746High· 7.5▾ Twilightjsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 18.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.7%
0.7% → 0.7%
In JSONata <v2.2.0, it is possible to craft non-matching inputs to the $toMillis function that cause superlinear backtracking in the ISO-8601 validation regex. This may lead to denial of service in applications that evaluate user-provided JSONata expressions.
This issue has been addressed in JSONata version >= 2.2.0 via fixes that include https://github.com/jsonata-js/jsonata/pull/782 and https://github.com/jsonata-js/jsonata/pull/793. Applications that evaluate user-provided expressions should update ASAP to prevent exploitation.
https://github.com/jsonata-js/jsonata/releases/tag/v2.2.0
Thank you to Doruk Tan Öztürk for disclosing this issue.
jsonata < 2.2.0Upgrade to a patched release:
jsonata 2.2.0Connected by shared product, vendor, weakness, or advisory.
CVE-2026-77413Critical· 9.8JSONata is a JSON query and transformation language
CVE-2026-12208Medium· 5.3jsonata: Function Binding Prototype Pollution via hasOwnProperty Override
CVE-2026-77414Critical· 9.8JSONata is a JSON query and transformation language
CVE-2026-77415Critical· 9.8JSONata is a JSON query and transformation language
CVE-2024-21538High· 7.5Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization
CVE-2024-21490High· 7.5This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0