Vulnerability record · CVE-2021-32723 · published 28 June 2021
CVE-2021-32723: Prismjs prism uncontrolled resource consumption vulnerability
PPrismjs · Prism
Prism is a syntax highlighting library. Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS). When Prism is used to highlight untrusted (user-given) text, an attacker can craft a string that will take a very very long time to highlight. This problem has been fixed in Prism v1.24. As a workaround, do not use ASCIIDoc or ERB to highlight untrusted text. Other languages are not affected and can be used to highlight untrusted text.
Description
Prism is a syntax highlighting library. Some languages before 1.24.0 are vulnerable to Regular Expression Denial of Service (ReDoS). When Prism is used to highlight untrusted (user-given) text, an attacker can craft a string that will take a very very long time to highlight. This problem has been fixed in Prism v1.24. As a workaround, do not use ASCIIDoc or ERB to highlight untrusted text. Other languages are not affected and can be used to highlight untrusted text.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/PrismJS/prism/pull/2688 | PatchThird Party Advisory |
| https://github.com/PrismJS/prism/pull/2774 | PatchThird Party Advisory |
| https://github.com/PrismJS/prism/security/advisories/GHSA-gj77-59wh-66hg | Third Party Advisory |
| https://www.oracle.com/security-alerts/cpujan2022.html | PatchThird Party Advisory |
| https://github.com/PrismJS/prism/pull/2688 | PatchThird Party Advisory |
| https://github.com/PrismJS/prism/pull/2774 | PatchThird Party Advisory |
| https://github.com/PrismJS/prism/security/advisories/GHSA-gj77-59wh-66hg | Third Party Advisory |
| https://www.oracle.com/security-alerts/cpujan2022.html | PatchThird Party Advisory |
Track CVE-2021-32723 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-32723), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.