Skip to content

Backport $toMillis security fixes to v1 (CVE-2026-52746) - #825

Merged
mattbaileyuk merged 2 commits into
jsonata-js:v1from
vadym-khodak:v1-tomillis-cve-backport
Jul 30, 2026
Merged

Backport $toMillis security fixes to v1 (CVE-2026-52746)#825
mattbaileyuk merged 2 commits into
jsonata-js:v1from
vadym-khodak:v1-tomillis-cve-backport

Conversation

@vadym-khodak

Copy link
Copy Markdown

Summary

Backports the $toMillis() security fixes for CVE-2026-52746 / GHSA-86vw-mfpg-wwv9 to the v1 branch, following the precedent of #815 (released as 1.8.8).

Cherry-picked from master with original authorship preserved:

Both applied cleanly to src/datetime.js.

Why

1.8.8 backported the prototype-pollution fixes but not this one, so the advisory's patched range is currently only >= 2.2.0. Migrating v1 users to 2.x is non-trivial (sync → async evaluate()), and 1.x remains widely depended upon.

Verification

ReDoS is neutralized. Non-matching input '2026' + '-11'.repeat(n) + 'x' passed to $toMillis():

n v1 (1.8.8) this branch
2,000 12 ms 0 ms
10,000 238 ms 0 ms
40,000 3,643 ms 1 ms

Tests pass. mocha test --recursive: 3330 passing. The 3 failures on this branch are identical on clean v1 (two timing-sensitive $now()/$millis() uniqueness assertions and the matchers group) — pre-existing, unrelated to this change.

Release request

Could you cut a 1.8.9 release with this (version bump left to maintainers, as with 1.8.8), and update GHSA-86vw-mfpg-wwv9's patched versions to include >= 1.8.9, < 2.0.0? The advisory update is what lets Dependabot/audit tooling recognize 1.8.9 as fixed.

…#782)

The factional part of the date/time seconds was being parsed
and converted to an integer in order to pass to the
milliseconds parameter. However, if there were more than
3 digits, then this would be more than a thousand and spill over
into the seconds (and possible minutes).
Moreover, if the fractional part started with a zero, this would get lost in the conversion to an integer.
This commit fixes the parsing and truncates the value to max 3 digits (milliseconds is the finest resolution supported).

Signed-off-by: Andrew Coleman <andrew_coleman@uk.ibm.com>
Signed-off-by: Andrew Coleman <andrew_coleman@uk.ibm.com>

@mattbaileyuk mattbaileyuk left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Thank you; the others were ported to focus on a particular issue at the time, but agree these should be ported too for that CVE

@mattbaileyuk
mattbaileyuk merged commit f659e42 into jsonata-js:v1 Jul 30, 2026
5 checks passed
@vadym-khodak
vadym-khodak deleted the v1-tomillis-cve-backport branch July 30, 2026 15:24
@vadym-khodak

Copy link
Copy Markdown
Author

@mattbaileyuk Could you please let me know what else should be done to release v 1.8.9 with this fix?

@mattbaileyuk

Copy link
Copy Markdown
Member

1.8.9 has now been released

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants