Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0839 | KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\edef` that causes a near-infinite loop, despite setting `maxExpand` to avoid such loops. This can be used as an availability attack, where e.g. a client rendering another user's KaTeX input will be unable to use the site due to memory overflow, tying up the main thread, or stack overflow. Upgrade to KaTeX v0.16.10 to remove this vulnerability. |
Github GHSA |
GHSA-64fm-8hw2-v72w | KaTeX's maxExpand bypassed by `\edef` |
Ubuntu USN |
USN-7572-1 | KaTeX vulnerabilities |
Thu, 05 Feb 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 05 Dec 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:katex:katex:*:*:*:*:*:*:*:* |
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-05T15:26:36.281Z
Reserved: 2024-03-07T14:33:30.036Z
Link: CVE-2024-28243
Updated: 2024-08-02T00:48:49.666Z
Status : Modified
Published: 2024-03-25T20:15:07.950
Modified: 2026-02-05T16:15:49.747
Link: CVE-2024-28243
No data.
OpenCVE Enrichment
Updated: 2025-07-13T11:31:12Z
EUVD
Github GHSA
Ubuntu USN