#VU50054 Input validation error in CKEditor - CVE-2021-26272
Published: January 26, 2021 / Updated: January 27, 2021
CKEditor
CKSource
Description
The vulnerability allows a remote attacker to perform a regular expression denial of service (ReDoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can trick the victim to paste a specially crafted URL-like text into the editor, and then press Enter or Space (in the Autolink plugin) and perform a regular expression denial of service (ReDoS) attack.