Jerryscript is a lightweight JavaScript engine designed for embedded and IoT environments, deployed across a wide range of constrained devices where memory and processing overhead must be minimal. Despite a narrow product footprint, the engine's ubiquity in embedded systems and its role as a foundational component in many IoT and edge-computing platforms give its vulnerability exposure disproportionate significance. Vulnerabilities affecting the engine skew toward serious outcomes, with a meaningful share reaching critical severity and concentrating in memory-safety weakness classes including out-of-bounds reads and writes, NULL-pointer dereferences, and reachable assertions—flaws characteristic of interpreter implementations handling untrusted input. Defenders should track Jerryscript releases closely, especially where instances are network-exposed or integrated into supply chains; live severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Jerryscript over time
Signals from CVEs in this vendor scope (98 CVEs).
98 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-43453CRITICAL A Heap-based Buffer Overflow vulnerability exists in JerryScript 2.4.0 and prior versions via an out-of-bounds read in parser_parse_for_statement_start in the js-parser-statm.c fil | Apr 7, 2022 | 9.8 | 31 | NO | NO |
CVE-2017-18212CRITICAL An issue was discovered in JerryScript 1.0. There is a heap-based buffer over-read in the lit_read_code_unit_from_hex function in lit/lit-char-helpers.c via a RegExp("[\x0"); paylo | Mar 1, 2018 | 9.8 | 31 | NO | NO |
CVE-2021-42863CRITICAL A buffer overflow in ecma_builtin_typedarray_prototype_filter() in JerryScript version fe3a5c0 allows an attacker to construct a fake object or a fake arraybuffer with unlimited si | May 12, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-41752CRITICAL Stack overflow vulnerability in Jerryscript before commit e1ce7dd7271288be8c0c8136eea9107df73a8ce2 on Oct 20, 2021 due to an unbounded recursive call to the new opt() function. | Apr 5, 2022 | 9.8 | 30 | NO | NO |
CVE-2021-41751CRITICAL Buffer overflow vulnerability in file ecma-builtin-array-prototype.c:909 in function ecma_builtin_array_prototype_object_slice in Jerryscript before commit e1ce7dd7271288be8c0c8136 | Apr 5, 2022 | 9.8 | 29 | NO | NO |
CVE-2020-23323CRITICAL There is a heap-buffer-overflow at re-parser.c in re_parse_char_escape in JerryScript 2.2.0. | Jun 10, 2021 | 9.8 | 29 | NO | NO |
CVE-2020-23321CRITICAL There is a heap-buffer-overflow at lit-strings.c:431 in lit_read_code_unit_from_utf8 in JerryScript 2.2.0. | Jun 10, 2021 | 9.8 | 29 | NO | NO |
CVE-2020-23302CRITICAL There is a heap-use-after-free at ecma-helpers-string.c:772 in ecma_ref_ecma_string in JerryScript 2.2.0 | Jun 10, 2021 | 9.8 | 29 | NO | NO |
CVE-2019-1010176CRITICAL JerryScript commit 4e58ccf68070671e1fff5cd6673f0c1d5b80b166 is affected by: Buffer Overflow. The impact is: denial of service and possibly arbitrary code execution. The component i | Jul 25, 2019 | 9.8 | 29 | NO | NO |
CVE-2020-22597CRITICAL An issue in Jerrscript- project Jerryscrip v. 2.3.0 allows a remote attacker to execute arbitrary code via the ecma_builtin_array_prototype_object_slice parameter. | Jul 3, 2023 | 9.8 | 28 | NO | NO |
Signals from CVEs in this vendor scope (98 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Jerryscript.
Media articles that mention a CVE ID that affects a product developed by Jerryscript — matched by CVE ID, not by vendor name.