CVE-2018-20801: Highcharts

High severity, CVSS 7.5. EPSS: 3.2% chance of exploitation in the next 30 days.

In js/parts/SvgRenderer.js in Highcharts JS before 6.1.0, the use of backtracking regular expressions permitted an attacker to conduct a denial of service attack against the SVGRenderer component, aka ReDoS.

Affected products

  • Highcharts Highcharts: before 6.1.0 (fixed in 6.1.0)

Published 2019-03-14. Last modified 2026-06-17.