REDHAT-BUG-2431930: High severity npm/jsdiff vulnerability

Published Jan 22, 2026
·
Updated

jsdiff is a JavaScript text differencing implementation. Prior to versions 8.0.3, 5.2.2, and 4.0.4, attempting to parse a patch whose filename headers contain the line break characters \r, \u2028, or \u2029 can cause the parsePatch method to enter an infinite loop. It then consumes memory without limit until the process crashes due to running out of memory. Applications are therefore likely to be vulnerable to a denial-of-service attack if they call parsePatch with a user-provided patch as input. A large payload is not needed to trigger the vulnerability, so size limits on user input do not provide any protection. Furthermore, some applications may be vulnerable even when calling parsePatch on a patch generated by the application itself if the user is nonetheless able to control the filename headers (e.g. by directly providing the filenames of the files to be diffed). The applyPatch method is similarly affected if (and only if) called with a string representation of a patch as an argument, since under the hood it parses that string using parsePatch. Other methods of the library are unaffected. Finally, a second and lesser interdependent bug - a ReDOS - also exhibits when those same line break characters are present in a patch's patch header (also known as its "leading garbage"). A maliciously-crafted patch header of length n can take parsePatch O(n³) time to parse. Versions 8.0.3, 5.2.2, and 4.0.4 contain a fix. As a workaround, do not attempt to parse patches that contain any of these characters: \r, \u2028, or \u2029.

Affected Software

1 affected component
npm/jsdiff>=<8.0.3, >=<5.2.2, >=<4.0.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade jsdiff to a version that resolves this vulnerability.

    Fixed in 8.0.3
  2. Upgrade

    Upgrade jsdiff to a version that resolves this vulnerability.

    Fixed in 5.2.2
  3. Upgrade

    Upgrade jsdiff to a version that resolves this vulnerability.

    Fixed in 4.0.4
  4. Configuration

    As a workaround, do not attempt to parse patches that contain any of these characters in the patch filename headers: \r, \u2028, \u2029. This mitigates the DoS/infinite loop behavior when parsePatch receives user-provided patch input.

    jsdiff parsePatch input patch filename headers = reject any patches whose filename headers contain line break characters \r, \u2028, or \u2029

Event History

Jan 22, 2026
Data Sourced
via Red Hat·03:01 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2431930?

The severity of REDHAT-BUG-2431930 is classified as high with a score of 7.

2

How do I fix REDHAT-BUG-2431930?

To fix REDHAT-BUG-2431930, update to jsdiff versions 8.0.3, 5.2.2, or 4.0.4 or later.

3

What causes the issue in REDHAT-BUG-2431930?

The issue in REDHAT-BUG-2431930 is caused by the `parsePatch` method entering an infinite loop when parsing a patch with specific line break characters in the filename headers.

4

What software is affected by REDHAT-BUG-2431930?

The affected software by REDHAT-BUG-2431930 is the npm package jsdiff.

5

When was REDHAT-BUG-2431930 published?

REDHAT-BUG-2431930 was published on January 22, 2026.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203