Inefficient regular expression complexity in tinymce - #VU131915
Published: January 6, 2021 / Updated: May 20, 2026
tinymce
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to inefficient regular expression complexity in the codesample plugin dependency when performing syntax highlighting of ruby code samples. A remote attacker can supply a poorly formed ruby code sample to cause a denial of service.
The issue can lock up the browser during syntax highlighting.