SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-52746

HIGH · CVSS 7.5 EPSS 0.38% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The vulnerability affects applications utilizing JSONata versions prior to 2.2.0 and 1.8.9, where maliciously crafted inputs to the $toMillis function can trigger superlinear backtracking in the ISO-8601 validation regex, resulting in denial of service. Organizations using affected versions should prioritize updating to the fixed releases to mitigate potential service disruptions caused by this exploit. This is particularly critical for applications that process user-provided JSONata expressions.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-52746
Severity
HIGH
CVSS
7.5
EPSS
0.38%

Original NVD Description

JSONata is a JSON query and transformation language. Prior to 2.2.0 and 1.8.9, malicious non-matching inputs to the $toMillis function can cause superlinear backtracking in the ISO-8601 validation regex, leading to denial of service in applications that evaluate user-provided JSONata expressions. This issue is fixed in version 2.2.0 and 1.8.9.

Related CVEs

Other vulnerabilities affecting the same vendor(s)