PT-2025-25754 · Unknown · Microlight

Rooting

+1

·

Published

2025-06-17

·

Updated

2025-06-26

·

CVE-2025-45526

CVSS v3.1

2.9

Low

VectorAV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions microlight version 0.0.7
Description A denial of service issue has been identified in the microlight JavaScript library. The library does not limit the size of textual content it processes in HTML elements with the microlight class. When excessively large content is processed, the reset function in microlight.js consumes excessive memory and CPU resources, causing browser crashes or unresponsiveness. An attacker can exploit this by tricking a user into visiting a malicious web page containing a microlight element with large content.
Recommendations For microlight version 0.0.7, consider disabling the library until a patch is available to prevent denial of service attacks. Restrict access to web pages that use the microlight library to minimize the risk of exploitation. Avoid using the microlight library for syntax highlighting until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2025-45526
GHSA-WGC6-9F6W-H8HX

Affected Products

Microlight