CVE-2026-52746
published 2026-07-17CVE-2026-52746: JSONata is a JSON query and transformation language. Prior to 2.2.0 and 1.8.9, malicious non-matching inputs to the $toMillis function can cause superlinear…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.69%
50.9th percentile
JSONata is a JSON query and transformation language. Prior to 2.2.0 and 1.8.9, malicious non-matching inputs to the $toMillis function can cause superlinear backtracking in the ISO-8601 validation regex, leading to denial of service in applications that evaluate user-provided JSONata expressions. This issue is fixed in version 2.2.0 and 1.8.9.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jsonata-js | jsonata | < 1.8.9 | 1.8.9 |
| jsonata-js | jsonata | — | — |
| jsonata | jsonata | < 2.2.0 | 2.2.0 |
| jsonata | jsonata | >= 0 < 2.2.0 | 2.2.0 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
jsonata-js jsonata up to 2.1.x ISO-8601 Validation toMillis incorrect regex
vuldb·2026-07-17·CVSS 7.5
CVE-2026-52746 [HIGH] jsonata-js jsonata up to 2.1.x ISO-8601 Validation toMillis incorrect regex
A vulnerability labeled as problematic has been found in jsonata-js jsonata up to 2.1.x. The impacted element is the function toMillis of the component ISO-8601 Validation. The manipulation results in incorrect regular expression.
This vulnerability is cataloged as CVE-2026-52746. The attack may be launched remotely. There is no exploit available.
GHSA
jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion
ghsa·2026-07-02
CVE-2026-52746 [HIGH] CWE-1333 jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion
jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion
### Impact
In JSONata `= 2.2.0 via fixes that include https://github.com/jsonata-js/jsonata/pull/782 and https://github.com/jsonata-js/jsonata/pull/793. Applications that evaluate user-provided expressions should update ASAP to prevent exploitation.
### References
https://github.com/jsonata-js/jsonata/releases/tag/v2.2.0
### Credit
Thank you to Doruk Tan Öztürk for disclosing this issue.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/jsonata-js/jsonata/commit/80ba95d170f74e3f20f4f36b8b77d8c85cea7686https://github.com/jsonata-js/jsonata/commit/d6ffc17cb16a8e53c222205bd274624e919cce0bhttps://github.com/jsonata-js/jsonata/pull/782https://github.com/jsonata-js/jsonata/pull/793https://github.com/jsonata-js/jsonata/releases/tag/v1.8.9https://github.com/jsonata-js/jsonata/releases/tag/v2.2.0https://github.com/jsonata-js/jsonata/security/advisories/GHSA-86vw-mfpg-wwv9
2026-07-17
Published