{"id":"GHSA-5pgg-2g8v-p4x9","summary":"SheetJS Regular Expression Denial of Service (ReDoS)","details":"SheetJS Community Edition before 0.20.2 is vulnerable.to Regular Expression Denial of Service (ReDoS).\n\nA non-vulnerable version cannot be found via npm, as the repository hosted on GitHub and the npm package `xlsx` are no longer maintained. Version 0.20.2 can be downloaded via https://cdn.sheetjs.com/.","aliases":["CVE-2024-22363"],"modified":"2026-07-17T21:11:35.382884568Z","published":"2024-04-05T06:30:46Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2024-04-08T13:47:03Z","nvd_published_at":"2024-04-05T06:15:10Z","cwe_ids":["CWE-1333"],"severity":"HIGH"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-22363"},{"type":"WEB","url":"https://cdn.sheetjs.com"},{"type":"WEB","url":"https://cdn.sheetjs.com/advisories/CVE-2024-22363"},{"type":"WEB","url":"https://cwe.mitre.org/data/definitions/1333.html"},{"type":"PACKAGE","url":"https://git.sheetjs.com/sheetjs/sheetjs"},{"type":"WEB","url":"https://git.sheetjs.com/sheetjs/sheetjs/src/tag/v0.20.2"}],"affected":[{"package":{"name":"xlsx","ecosystem":"npm","purl":"pkg:npm/xlsx"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/04/GHSA-5pgg-2g8v-p4x9/GHSA-5pgg-2g8v-p4x9.json","last_known_affected_version_range":"\u003c 0.20.2"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}