Junglewise Threat Intelligence

CVE-2026-24001: jsdiff denial of service in parsePatch and applyPatch

CVE-2026-24001 · Severity: high · CVSS 7.5 · Published 2026-01-22

Vendors: Red Hat.

Executive brief

jsdiff is a JavaScript library used to compare text and generate or apply patches. A vulnerability in how it handles specific line-break characters allows an attacker to crash an application by providing a specially crafted patch file. This results in a denial-of-service (DoS) where the application consumes all available memory and stops functioning.

Technical details

The jsdiff library contains a logic flaw in its `parsePatch` method where certain line-break characters (\r, \u2028, or \u2029) in filename headers cause an inconsistency between regex checks. This leads to an infinite loop that consumes memory until the process crashes (OOM). Additionally, a secondary ReDoS vulnerability exists in the patch header parsing logic, where maliciously crafted headers can trigger O(n³) time complexity. The `applyPatch` method is also affected when processing string inputs as it relies on `parsePatch` internally. Fixes are available in versions 8.0.3, 5.2.2, 4.0.4, and 3.5.1.

Affected products

  • kpdecker jsdiff < 3.5.1, >= 4.0.0 < 4.0.4, >= 5.0.0 < 5.2.2, >= 6.0.0 < 8.0.3
  • Red Hat Red Hat Satellite 6

Timeline

  • 2026-01-07: patched: Initial fix merged in pull request 649
  • 2026-01-14: advisory: GitHub Security Advisory GHSA-73rr-hh4g-fpgx published
  • 2026-01-22: disclosed: CVE-2026-24001 published to NVD

References