[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"repo-stars":3,"vuln-CVE-2019-20922":6},{"stargazers_count":4,"fetched_at":5},7,"2026-06-05T02:55:30.529Z",{"id":7,"descriptions":8,"cisa":9,"weaknesses":10,"exploits":86,"aliases":87,"duplicate_of":9,"upstream":89,"downstream":90,"duplicates":95,"related":96,"reserved_at":9,"published_at":97,"modified_at":98,"state":99,"summary":100,"references_raw":109,"kevs":137,"epss":138,"epss_history":141,"metrics":410,"affected":422},"CVE-2019-20922","Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templates. This may allow attackers to exhaust system resources.",null,[11],{"_key":12,"id":12,"name":13,"description":14,"type":15,"status":16,"abstraction":17,"likelihood_of_exploit":18,"capec":19},"CWE-400","Uncontrolled Resource Consumption","The product does not properly control the allocation and maintenance of a limited resource.","weakness","Draft","Class","High",[20,24,82],{"id":21,"name":22,"techniques":23},"CAPEC-147","XML Ping of the Death",[],{"id":25,"name":26,"techniques":27},"CAPEC-227","Sustained Client Engagement",[28],{"id":29,"name":30,"tactics":31,"countermeasures":35},"T1499","Endpoint Denial of Service",[32],{"id":33,"name":34},"TA0105","Impact",[36,41,45,49,53,57,61,65,69,73,78],{"id":37,"name":38,"tactic":39},"D3-UGLPA","User Geolocation Logon Pattern Analysis",{"name":40},"Detect",{"id":42,"name":43,"tactic":44},"D3-PMAD","Protocol Metadata Anomaly Detection",{"name":40},{"id":46,"name":47,"tactic":48},"D3-CSPP","Client-server Payload Profiling",{"name":40},{"id":50,"name":51,"tactic":52},"D3-PHDURA","Per Host Download-Upload Ratio Analysis",{"name":40},{"id":54,"name":55,"tactic":56},"D3-NTSA","Network Traffic Signature Analysis",{"name":40},{"id":58,"name":59,"tactic":60},"D3-APCA","Application Protocol Command Analysis",{"name":40},{"id":62,"name":63,"tactic":64},"D3-NTCD","Network Traffic Community Deviation",{"name":40},{"id":66,"name":67,"tactic":68},"D3-RTSD","Remote Terminal Session Detection",{"name":40},{"id":70,"name":71,"tactic":72},"D3-ISVA","Inbound Session Volume Analysis",{"name":40},{"id":74,"name":75,"tactic":76},"D3-NTF","Network Traffic Filtering",{"name":77},"Isolate",{"id":79,"name":80,"tactic":81},"D3-ITF","Inbound Traffic Filtering",{"name":77},{"id":83,"name":84,"techniques":85},"CAPEC-492","Regular Expression Exponential Blowup",[],[],[88],"GHSA-62gr-4qp9-h98f",[],[91,93],{"_key":92},"UBUNTU-CVE-2019-20922",{"_key":94},"RHSA-2020:5179",[],[],"2020-09-30T12:30:22.000Z","2024-08-05T03:00:18.954Z","Modified",{"cisa_kev":101,"cisa_ransomware":101,"cisa_vendor":9,"epss_severity":102,"epss_score":103,"severity":104,"severity_score":105,"severity_version":106,"severity_source":107,"severity_vector":108,"severity_status":99},false,"low",0.00291,"high",7.8,"v2.0","nvd","AV:N/AC:L/Au:N/C:N/I:N/A:C",[110,119,123,128,133],{"url":111,"sources":112,"tags":115},"https://www.npmjs.com/advisories/1300",[113,107,114],"cve.org","osv_npm",[116,117,118],"X Refsource MISC","Third Party Advisory","WEB",{"url":120,"sources":121,"tags":122},"https://snyk.io/vuln/SNYK-JS-HANDLEBARS-480388",[113,107,114],[116,117,118],{"url":124,"sources":125,"tags":126},"https://github.com/handlebars-lang/handlebars.js/commit/8d5530ee2c3ea9f0aee3fde310b9f36887d00b8b",[113,107,114],[116,127,117,118],"Patch",{"url":129,"sources":130,"tags":131},"https://nvd.nist.gov/vuln/detail/CVE-2019-20922",[114],[132],"Advisory",{"url":134,"sources":135,"tags":136},"https://www.npmjs.com/package/handlebars",[114],[118],[],{"date":139,"score":103,"percentile":140},"2026-06-04",0.52739,[142,146,149,152,154,157,160,163,166,169,172,175,178,181,184,188,191,194,197,200,203,206,209,212,215,218,221,224,227,230,233,236,239,242,245,248,251,253,256,259,262,266,269,271,274,277,280,283,286,289,292,295,298,301,303,306,309,312,315,318,321,324,327,330,333,336,339,341,344,347,350,353,357,360,363,366,369,372,375,378,381,384,387,390,393,396,398,401,404,406],{"date":143,"score":144,"percentile":145},"2025-11-04",0.00131,0.33415,{"date":147,"score":144,"percentile":148},"2025-11-05",0.33399,{"date":150,"score":144,"percentile":151},"2025-11-06",0.33398,{"date":153,"score":144,"percentile":145},"2025-11-07",{"date":155,"score":144,"percentile":156},"2025-11-08",0.33413,{"date":158,"score":144,"percentile":159},"2025-11-09",0.3339,{"date":161,"score":144,"percentile":162},"2025-11-10",0.33336,{"date":164,"score":144,"percentile":165},"2025-11-11",0.33361,{"date":167,"score":144,"percentile":168},"2025-11-12",0.33407,{"date":170,"score":144,"percentile":171},"2025-11-13",0.33421,{"date":173,"score":144,"percentile":174},"2025-11-14",0.33426,{"date":176,"score":144,"percentile":177},"2025-11-15",0.33424,{"date":179,"score":144,"percentile":180},"2025-11-16",0.33394,{"date":182,"score":144,"percentile":183},"2025-11-17",0.33365,{"date":185,"score":186,"percentile":187},"2025-11-18",0.00581,0.66348,{"date":189,"score":186,"percentile":190},"2025-11-19",0.66356,{"date":192,"score":186,"percentile":193},"2025-11-20",0.66351,{"date":195,"score":144,"percentile":196},"2025-11-21",0.33403,{"date":198,"score":144,"percentile":199},"2025-11-22",0.33408,{"date":201,"score":144,"percentile":202},"2025-11-23",0.33374,{"date":204,"score":144,"percentile":205},"2025-11-24",0.33349,{"date":207,"score":144,"percentile":208},"2025-11-25",0.33344,{"date":210,"score":144,"percentile":211},"2025-11-26",0.3334,{"date":213,"score":144,"percentile":214},"2025-11-27",0.33348,{"date":216,"score":144,"percentile":217},"2025-11-28",0.3333,{"date":219,"score":144,"percentile":220},"2025-11-29",0.33311,{"date":222,"score":144,"percentile":223},"2025-11-30",0.3329,{"date":225,"score":144,"percentile":226},"2025-12-01",0.33382,{"date":228,"score":144,"percentile":229},"2025-12-02",0.33396,{"date":231,"score":144,"percentile":232},"2025-12-03",0.33395,{"date":234,"score":144,"percentile":235},"2025-12-04",0.33294,{"date":237,"score":144,"percentile":238},"2025-12-05",0.33329,{"date":240,"score":144,"percentile":241},"2025-12-06",0.33333,{"date":243,"score":144,"percentile":244},"2025-12-07",0.33312,{"date":246,"score":144,"percentile":247},"2025-12-08",0.33324,{"date":249,"score":144,"percentile":250},"2025-12-09",0.33368,{"date":252,"score":144,"percentile":177},"2025-12-10",{"date":254,"score":144,"percentile":255},"2025-12-11",0.33445,{"date":257,"score":144,"percentile":258},"2025-12-12",0.33474,{"date":260,"score":144,"percentile":261},"2025-12-13",0.33458,{"date":263,"score":264,"percentile":265},"2025-12-14",0.00226,0.45293,{"date":267,"score":264,"percentile":268},"2025-12-15",0.45275,{"date":270,"score":264,"percentile":265},"2025-12-16",{"date":272,"score":264,"percentile":273},"2025-12-17",0.45321,{"date":275,"score":264,"percentile":276},"2025-12-18",0.45367,{"date":278,"score":264,"percentile":279},"2025-12-19",0.45379,{"date":281,"score":264,"percentile":282},"2025-12-20",0.45352,{"date":284,"score":264,"percentile":285},"2025-12-21",0.4532,{"date":287,"score":264,"percentile":288},"2025-12-22",0.45298,{"date":290,"score":264,"percentile":291},"2025-12-23",0.45297,{"date":293,"score":264,"percentile":294},"2025-12-24",0.45308,{"date":296,"score":264,"percentile":297},"2025-12-25",0.45357,{"date":299,"score":264,"percentile":300},"2025-12-26",0.45339,{"date":302,"score":264,"percentile":297},"2025-12-27",{"date":304,"score":264,"percentile":305},"2025-12-28",0.45273,{"date":307,"score":264,"percentile":308},"2025-12-29",0.45257,{"date":310,"score":264,"percentile":311},"2025-12-30",0.45252,{"date":313,"score":264,"percentile":314},"2025-12-31",0.45295,{"date":316,"score":144,"percentile":317},"2026-01-01",0.33532,{"date":319,"score":144,"percentile":320},"2026-01-02",0.33519,{"date":322,"score":144,"percentile":323},"2026-01-03",0.33505,{"date":325,"score":264,"percentile":326},"2026-01-04",0.45237,{"date":328,"score":264,"percentile":329},"2026-01-05",0.45222,{"date":331,"score":264,"percentile":332},"2026-01-06",0.45227,{"date":334,"score":264,"percentile":335},"2026-01-07",0.45245,{"date":337,"score":264,"percentile":338},"2026-01-08",0.45271,{"date":340,"score":264,"percentile":335},"2026-01-09",{"date":342,"score":264,"percentile":343},"2026-01-10",0.45239,{"date":345,"score":264,"percentile":346},"2026-01-11",0.45218,{"date":348,"score":264,"percentile":349},"2026-01-12",0.45168,{"date":351,"score":264,"percentile":352},"2026-01-13",0.45145,{"date":354,"score":355,"percentile":356},"2026-01-14",0.00295,0.5244,{"date":358,"score":355,"percentile":359},"2026-01-15",0.52441,{"date":361,"score":355,"percentile":362},"2026-01-16",0.5246,{"date":364,"score":355,"percentile":365},"2026-01-17",0.52442,{"date":367,"score":355,"percentile":368},"2026-01-18",0.52428,{"date":370,"score":355,"percentile":371},"2026-01-19",0.52411,{"date":373,"score":355,"percentile":374},"2026-01-20",0.52409,{"date":376,"score":355,"percentile":377},"2026-01-21",0.52416,{"date":379,"score":355,"percentile":380},"2026-01-22",0.52422,{"date":382,"score":355,"percentile":383},"2026-01-23",0.52468,{"date":385,"score":355,"percentile":386},"2026-01-24",0.52476,{"date":388,"score":355,"percentile":389},"2026-01-25",0.5243,{"date":391,"score":355,"percentile":392},"2026-01-26",0.5241,{"date":394,"score":355,"percentile":395},"2026-01-27",0.52417,{"date":397,"score":355,"percentile":368},"2026-01-28",{"date":399,"score":355,"percentile":400},"2026-01-29",0.52427,{"date":402,"score":355,"percentile":403},"2026-01-30",0.52426,{"date":405,"score":355,"percentile":389},"2026-01-31",{"date":407,"score":408,"percentile":409},"2026-02-01",0.00171,0.38728,[411,420],{"source":107,"cvss_v2_0":412,"cvss_v3_0":9,"cvss_v3_1":415,"cvss_v4_0":9},{"baseScore":105,"baseSeverity":9,"vectorString":108,"impactScore":413,"exploitabilityScore":414},6.9,10,{"baseScore":416,"baseSeverity":417,"vectorString":418,"impactScore":419,"exploitabilityScore":414},7.5,"HIGH","CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",6,{"source":114,"cvss_v2_0":9,"cvss_v3_0":9,"cvss_v3_1":421,"cvss_v4_0":9},{"baseScore":416,"baseSeverity":9,"vectorString":418,"impactScore":419,"exploitabilityScore":414},[423,436],{"ecosystem":9,"name":424,"vendor":425,"product":424,"cpe_part":426,"purl_type":9,"purl_namespace":9,"purl_name":9,"source":9,"versions":427},"handlebars","handlebarsjs","a",[428],{"version":429,"is_range":430,"range_type":431,"version_start":432,"version_start_type":433,"version_end":434,"version_end_type":435,"fixed_in":9},"gte4.0.0_lt4.4.5",true,"cpe","4.0.0","including","4.4.5","excluding",{"ecosystem":437,"name":424,"vendor":437,"product":424,"cpe_part":9,"purl_type":438,"purl_namespace":9,"purl_name":424,"source":9,"versions":439},"Npm","npm",[440],{"version":441,"is_range":430,"range_type":442,"version_start":432,"version_start_type":433,"version_end":434,"version_end_type":435,"fixed_in":9},"gte4_0_0_lt4_4_5","semver"]