debian · CVE-2024-28243

Quick triage

Priority: not yet assigned Published: Updated: Sun, 05 Jul 2026 10:47:54 GMT

View at Official debian advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2024-28243 not yet assigned priority: Debian including 1 source packages (node-katex), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 3, open 2.

Description:

KaTeX is a JavaScript library for TeX math rendering on the web. KaTeX users who render untrusted mathematical expressions could encounter malicious input using `\edef` that causes a near-infinite loop, despite setting `maxExpand` to avoid such loops. This can be used as an availability attack, where e.g. a client rendering another user's KaTeX input will be unable to use the site due to memory overflow, tying up the main thread, or stack overflow. Upgrade to KaTeX v0.16.10 to remove this vulnerability.

cvelogic Threat Intelligence