An issue in Cesanta mjs 2.20.0 allows a remote attacker to cause a denial of service via the mjsarraylength function in the mjs.c file.