Loading
Generated remediation guidance and an executive summary. No account required.
In js/parts/SvgRenderer.js in Highcharts JS before 6.1.0, the use of backtracking regular expressions permitted an attacker to conduct a denial of service attack against the SVGRenderer component, aka ReDoS.
Cite this page
CVE-2018-20801. CVEDatabase.com. Retrieved 1 May 2026. https://cvedatabase.com/cve/CVE-2018-20801
Use CWE-185, Highcharts vendor hub and Highcharts product page to widen CVE-2018-20801 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-29489 for nearby disclosures in the same product family.