← Vulnerability feed

Vulnerability record · CVE-2020-7760 · published 30 October 2020

CVE-2020-7760: Codemirror uncontrolled resource consumption vulnerability

Codemirror · Codemirror

This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expression is located in https://github.com/codemirror/CodeMirror/blob/cdb228ac736369c685865b122b736cd0d397836c/mode/javascript/javascript.jsL129. The ReDOS vulnerability of the regex is mainly due to the sub-pattern (s|/*.*?*/)*

7.5 CVSS 3.1 High EPSS 5.3% · top 7.7% CWE-400 · Uncontrolled resource consumption
7.5CVSS 3.1 base score, v2 5.0
5.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
6Affected product versions listed by NVD
24References, 14 tagged exploit
17 Jun 2026Last modified by NVD

Description

This affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expression is located in https://github.com/codemirror/CodeMirror/blob/cdb228ac736369c685865b122b736cd0d397836c/mode/javascript/javascript.jsL129. The ReDOS vulnerability of the regex is mainly due to the sub-pattern (s|/*.*?*/)*

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

6 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/codemirror/CodeMirror/commit/55d0333907117c9231ffdf555ae8824705993bbb PatchThird Party Advisory
https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEMARMOTTAWEBJARS-1024450 ExploitThird Party Advisory
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1024449 ExploitThird Party Advisory
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1024445 ExploitThird Party Advisory
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBCODEMIRROR-1024448 ExploitThird Party Advisory
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBCOMPONENTS-1024446 ExploitThird Party Advisory
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1024447 ExploitThird Party Advisory
https://snyk.io/vuln/SNYK-JS-CODEMIRROR-1016937 ExploitThird Party Advisory
https://www.debian.org/security/2020/dsa-4789 Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html PatchThird Party Advisory
https://github.com/codemirror/CodeMirror/commit/55d0333907117c9231ffdf555ae8824705993bbb PatchThird Party Advisory
https://snyk.io/vuln/SNYK-JAVA-ORGAPACHEMARMOTTAWEBJARS-1024450 ExploitThird Party Advisory
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1024449 ExploitThird Party Advisory
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1024445 ExploitThird Party Advisory
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBCODEMIRROR-1024448 ExploitThird Party Advisory
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBCOMPONENTS-1024446 ExploitThird Party Advisory
https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1024447 ExploitThird Party Advisory
https://snyk.io/vuln/SNYK-JS-CODEMIRROR-1016937 ExploitThird Party Advisory
https://www.debian.org/security/2020/dsa-4789 Third Party Advisory
https://www.oracle.com//security-alerts/cpujul2021.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuApr2021.html PatchThird Party Advisory
https://www.oracle.com/security-alerts/cpuapr2022.html PatchThird Party Advisory

Track CVE-2020-7760 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.1CVE-2020-11023jQuery DOM manipulation methods XSS via untrusted HTML option elementsjQuery versions 1.0.3 through before 3.5.0 execute untrusted code when HTML containing <option> elements from untrusted sources is passed to DOM mani…KEVEPSS 85%analysed10.0CVE-2026-70880Oracle hyperion data relationship management improper access control vulnerabilityVulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version …EPSS 0.51%10.0CVE-2008-1822Oracle application express vulnerabilityUnspecified vulnerability in the Oracle Application Express component in Oracle Application Express 3.0.1 has unknown impact and remote attack vector…EPSS 2.1%9.8CVE-2026-70871Oracle hyperion data relationship management improper access control vulnerabilityVulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version …EPSS 0.51%9.8CVE-2026-70873Oracle hyperion data relationship management improper access control vulnerabilityVulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and security). The supported version …EPSS 0.51%9.8CVE-2026-70689Oracle essbase improper access control vulnerabilityVulnerability in Oracle Essbase (component: Infrastructure). The supported version that is affected is 21.8.1.0.0. Easily exploitable vulnerability a…EPSS 0.51%9.8CVE-2022-23305Log4j 1.x JDBCAppender SQL injection via logged inputThe JDBCAppender in Log4j 1.2.x builds SQL statements from configuration parameters and PatternLayout converters, so logged values such as the %m mes…EPSS 67%analysed9.8CVE-2021-3711OpenSSL SM2 decryption buffer overflowOpenSSL's SM2 decryption code miscalculates the output buffer size needed by EVP_PKEY_decrypt(), so the first sizing call can return a value smaller …EPSS 88%analysed

Source: NIST National Vulnerability Database (record CVE-2020-7760), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.