← Vulnerability feed

Vulnerability record · CVE-2021-32723 · published 28 June 2021

CVE-2021-32723: Prismjs prism uncontrolled resource consumption vulnerability

PPrismjs · Prism

Prism is a syntax highlighting library. Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS). When Prism is used to highlight untrusted (user-given) text, an attacker can craft a string that will take a very very long time to highlight. This problem has been fixed in Prism v1.24. As a workaround, do not use ASCIIDoc or ERB to highlight untrusted text. Other languages are not affected and can be used to highlight untrusted text.

6.5 CVSS 3.1 Medium EPSS 1.4% · top 28.1% CWE-400 · Uncontrolled resource consumption
6.5CVSS 3.1 base score, v2 4.3
1.4%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

Prism is a syntax highlighting library. Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS). When Prism is used to highlight untrusted (user-given) text, an attacker can craft a string that will take a very very long time to highlight. This problem has been fixed in Prism v1.24. As a workaround, do not use ASCIIDoc or ERB to highlight untrusted text. Other languages are not affected and can be used to highlight untrusted text.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-32723 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

6.1CVE-2020-11023jQuery DOM manipulation methods XSS via untrusted HTML option elementsjQuery versions 1.0.3 through before 3.5.0 execute untrusted code when HTML containing <option> elements from untrusted sources is passed to DOM mani…KEVEPSS 85%analysed10.0CVE-2008-1822Oracle application express vulnerabilityUnspecified vulnerability in the Oracle Application Express component in Oracle Application Express 3.0.1 has unknown impact and remote attack vector…EPSS 2.1%9.0CVE-2025-50067Oracle application express open redirect vulnerabilityVulnerability in Oracle Application Express (component: Strategic Planner Starter App). Supported versions that are affected are 24.2.4 and 24.2.5. E…EPSS 0.29%9.0CVE-2023-21974Oracle application express vulnerabilityVulnerability in the Application Express Team Calendar Plugin product of Oracle Application Express (component: User Account). Supported versions tha…EPSS 0.61%9.0CVE-2023-21975Oracle application express vulnerabilityVulnerability in the Application Express Customers Plugin product of Oracle Application Express (component: User Account). Supported versions that ar…EPSS 0.61%7.5CVE-2022-24729Ckeditor uncontrolled resource consumption vulnerabilityCKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plug…EPSS 2.4%7.5CVE-2021-23341Prismjs prism vulnerabilityThe package prismjs before 1.23.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the prism-asciidoc, prism-rest, prism-tap and pr…EPSS 3.2%7.5CVE-2020-7760Codemirror uncontrolled resource consumption vulnerabilityThis affects the package codemirror before 5.58.2; the package org.apache.marmotta.webjars:codemirror before 5.58.2. The vulnerable regular expressio…EPSS 5.3%

Source: NIST National Vulnerability Database (record CVE-2021-32723), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.