CVE-2020-24345: Jerryscript
High severity, CVSS 7.8. EPSS: 0.8% chance of exploitation in the next 30 days.
JerryScript through 2.3.0 allows stack consumption via function a(){new new Proxy(a,{})}JSON.parse("[]",a). NOTE: the vendor states that the problem is the lack of the --stack-limit option
Affected products
- Jerryscript Jerryscript: up to and including 2.3.0
Published 2020-08-13. Last modified 2026-06-17.