{"id":"CVE-2021-23446","aliases":["GHSA-hf66-r44g-p7j9"],"url":"https://o3.security/vulnerability/CVE-2021-23446","summary":"Inefficient Regular Expression Complexity in handsontable","details":"The package handsontable before 10.0.0; the package handsontable from 0 and before 10.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) in Handsontable.helper.isNumeric function.","published":"2021-09-29T17:15:06.987Z","modified":"2026-07-09T01:07:42.885823Z","cvss":{"score":7.5,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":6,"affectedPackages":[{"ecosystem":"npm","name":"handsontable","fixedVersion":"10.0.0"}],"fix":{"url":"https://github.com/handsontable/handsontable/pull/8742","label":"handsontable/handsontable#8742"},"references":[{"type":"ADVISORY","url":"https://github.com/handsontable/handsontable/issues/8752"},{"type":"FIX","url":"https://github.com/handsontable/handsontable/pull/8742"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-DOTNET-HANDSONTABLE-1726793"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARS-1726795"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWER-1726796"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSBOWERGITHUBHANDSONTABLE-1726794"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JAVA-ORGWEBJARSNPM-1726797"},{"type":"EVIDENCE","url":"https://snyk.io/vuln/SNYK-JS-HANDSONTABLE-1726770"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-09T01:07:42.885823Z"}}