PT-2025-25754 · Unknown · Microlight
Rooting
+1
·
Published
2025-06-17
·
Updated
2025-06-26
·
CVE-2025-45526
CVSS v3.1
2.9
Low
| Vector | AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
microlight version 0.0.7
Description
A denial of service issue has been identified in the microlight JavaScript library. The library does not limit the size of textual content it processes in HTML elements with the microlight class. When excessively large content is processed, the reset function in microlight.js consumes excessive memory and CPU resources, causing browser crashes or unresponsiveness. An attacker can exploit this by tricking a user into visiting a malicious web page containing a microlight element with large content.
Recommendations
For microlight version 0.0.7, consider disabling the library until a patch is available to prevent denial of service attacks. Restrict access to web pages that use the microlight library to minimize the risk of exploitation. Avoid using the microlight library for syntax highlighting until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Microlight