CVE-2019-20922: Handlebarsjs Handlebars

High severity, CVSS 7.5. EPSS: 3.7% chance of exploitation in the next 30 days.

Handlebars before 4.4.5 allows Regular Expression Denial of Service (ReDoS) because of eager matching. The parser may be forced into an endless loop while processing crafted templates. This may allow attackers to exhaust system resources.

Affected products

  • Handlebarsjs Handlebars: from 4.0.0, before 4.4.5 (fixed in 4.4.5)

Published 2020-09-30. Last modified 2026-06-17.