CVE-2020-24345: Jerryscript

High severity, CVSS 7.8. EPSS: 0.8% chance of exploitation in the next 30 days.

JerryScript through 2.3.0 allows stack consumption via function a(){new new Proxy(a,{})}JSON.parse("[]",a). NOTE: the vendor states that the problem is the lack of the --stack-limit option

Affected products

Published 2020-08-13. Last modified 2026-06-17.