CVE-2023-39663: High severity mathjax vulnerability
DISPUTED Mathjax up to v2.7.9 was discovered to contain two Regular expression Denial of Service (ReDoS) vulnerabilities in MathJax.js via the components pattern and markdownPattern. NOTE: the vendor disputes this because the regular expressions are not applied to user input; thus, there is no risk.
Other sources
Mathjax is vulnerable to a denial of service, caused by two Regular expression Denial of Service (ReDoS) vulnerabilities in MathJax.js. By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause a denial of service.
— IBM
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Mathjax vulnerability?
The vulnerability ID of this Mathjax vulnerability is CVE-2023-39663.
What is the severity of CVE-2023-39663?
The severity of CVE-2023-39663 is high.
What is the affected software of CVE-2023-39663?
The affected software of CVE-2023-39663 is Mathjax up to version 2.7.9.
What type of vulnerability is CVE-2023-39663?
CVE-2023-39663 is a Regular expression Denial of Service (ReDoS) vulnerability.
Is there a fix available for CVE-2023-39663?
Yes, a fix is available for CVE-2023-39663. Please refer to the vendor's advisory or update to a patched version of Mathjax.