cvedb.io
CVE-2021-43843
MEDIUM · CVSS 5.3
EPSS exploitation probability: 0%
Published 2021-12-20T22:15:07.817 · Last modified 2026-06-17T04:11:33.273

Summary

jsx-slack is a package for building JSON objects for Slack block kit surfaces from JSX. The maintainers found the patch for CVE-2021-43838 in jsx-slack v4.5.1 is insufficient tfor protection from a Regular Expression Denial of Service (ReDoS) attack. If an attacker can put a lot of JSX elements into `<blockquote>` tag _with including multibyte characters_, an internal regular expression for escaping characters may consume an excessive amount of computing resources. v4.5.1 passes the test against ASCII characters but misses the case of multibyte characters. jsx-slack v4.5.2 has updated regular expressions for escaping blockquote characters to prevent catastrophic backtracking. It is also including an updated test case to confirm rendering multiple tags in `<blockquote>` with multibyte chara

Affected products

jsx-slack_project — jsx-slack

Does this affect you?

Add your gear to cvedb and we'll alert you only when jsx-slack_project ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.