CVE-2024-9506: Vue

Low severity, CVSS 3.7. EPSS: 0.5% chance of exploitation in the next 30 days.

Improper regular expression in Vue's parseHTML function leads to a potential regular expression denial of service vulnerability.

Affected products

  • Vue Vue: from 2.0.0, up to and including 2.7.16

Published 2024-10-15. Last modified 2026-06-17.