Executive brief
jsdiff is a JavaScript library used to compare text and generate or apply patches. A vulnerability in how it handles specific line-break characters allows an attacker to crash an application by providing a specially crafted patch file. This results in a denial-of-service (DoS) where the application consumes all available memory and stops functioning.
Technical details
The jsdiff library contains a logic flaw in its `parsePatch` method where certain line-break characters (\r, \u2028, or \u2029) in filename headers cause an inconsistency between regex checks. This leads to an infinite loop that consumes memory until the process crashes (OOM). Additionally, a secondary ReDoS vulnerability exists in the patch header parsing logic, where maliciously crafted headers can trigger O(n³) time complexity. The `applyPatch` method is also affected when processing string inputs as it relies on `parsePatch` internally. Fixes are available in versions 8.0.3, 5.2.2, 4.0.4, and 3.5.1.
Affected products
- kpdecker jsdiff < 3.5.1, >= 4.0.0 < 4.0.4, >= 5.0.0 < 5.2.2, >= 6.0.0 < 8.0.3
- Red Hat Red Hat Satellite 6
Timeline
- 2026-01-07: patched: Initial fix merged in pull request 649
- 2026-01-14: advisory: GitHub Security Advisory GHSA-73rr-hh4g-fpgx published
- 2026-01-22: disclosed: CVE-2026-24001 published to NVD
References
- https://github.com/kpdecker/jsdiff/commit/15a1585230748c8ae6f8274c202e0c87309142f5
- https://github.com/kpdecker/jsdiff/issues/653
- https://github.com/kpdecker/jsdiff/pull/649
- https://github.com/kpdecker/jsdiff/security/advisories/GHSA-73rr-hh4g-fpgx
- https://access.redhat.com/security/cve/CVE-2026-24001
- https://bugzilla.redhat.com/show_bug.cgi?id=2431930
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-24001.json