Alerts This Week
Warning Icon 1 606
Alerts This Week
Warning Icon 1 606

Ubuntu 20.04 LTS Highlight.js Critical Denial of Service USN-8276-1

ubuntu
Calendar Grey May 19, 2026
Dist Ubuntu Esm H88
Highlight.js on Ubuntu can crash with malicious input. Update urgently to prevent denial of service.
Highlight.js could be made to crash if it received specially crafted input.

Summary

Highlight.js could be made to crash if it received specially crafted

input.

Software Description:

- highlight.js: JavaScript syntax highlighter

Details:

It was discovered that Highlight.js used plain JavaScript objects for

internal language name lookups, making them susceptible to prototype

pollution attacks. An attacker could use this to cause a denial of

service or unexpected application behaviour.

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 20.04 LTS
  libjs-highlight.js              9.12.0+dfsg1-5ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  node-highlight.js               9.12.0+dfsg1-5ubuntu0.1~esm1
                                  Available with Ubuntu Pro

Ubuntu 18.04 LTS
  libjs-highlight.js              9.12.0+dfsg1-4ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  node-highlight.js               9.12.0+dfsg1-4ubuntu0.1~esm1
                                  Available with Ubuntu Pro

Ubuntu 16.04 LTS
  libjs-highlight.js              8.2+ds-4ubuntu0.1~esm1
                                  Available with Ubuntu Pro
  node-highlight.js               8.2+ds-4ubuntu0.1~esm1
                                  Available with Ubuntu Pro

In general, a standard system update will make all the necessary changes.

References

https://ubuntu.com/security/notices/USN-8276-1

CVE-2020-26237

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-8276-1

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here