It was possible to interrupt the processing of a RegExp...
Moderate severity
Unreviewed
Published
Mar 4, 2025
to the GitHub Advisory Database
•
Updated Mar 5, 2025
Description
Published by the National Vulnerability Database
Mar 4, 2025
Published to the GitHub Advisory Database
Mar 4, 2025
Last updated
Mar 5, 2025
It was possible to interrupt the processing of a RegExp bailout and run additional JavaScript, potentially triggering garbage collection when the engine was not expecting it. This vulnerability affects Firefox < 136 and Firefox ESR < 128.8.
References