> USN-8276-1: Highlight.js vulnerability
[DATE: 19/05/2026 18:38]
[LANGUAGE: EN]
It was discovered that Highlight.js used plain JavaScript objects for
internal language name lookups, making them susceptible to prototype
pollution attacks. An attacker could use this to cause a denial of
service or unexpected application behaviour.