SheetJS Regular Expression Denial of Service (ReDoS)
        
  High severity
        
          GitHub Reviewed
      
        Published
          Apr 5, 2024 
          to the GitHub Advisory Database
          •
          Updated Sep 19, 2025 
      
  
Description
        Published by the National Vulnerability Database
      Apr 5, 2024 
    
  
        Published to the GitHub Advisory Database
      Apr 5, 2024 
    
  
        Reviewed
      Apr 8, 2024 
    
  
        Last updated
      Sep 19, 2025 
    
  
SheetJS Community Edition before 0.20.2 is vulnerable.to Regular Expression Denial of Service (ReDoS).
A non-vulnerable version cannot be found via npm, as the repository hosted on GitHub and the npm package
xlsxare no longer maintained. Version 0.20.2 can be downloaded via https://cdn.sheetjs.com/.References