Common Weakness Enumeration

CWE-1333

Allowed

Inefficient Regular Expression Complexity

Abstraction: Base · Status: Draft

The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

885 vulnerabilities reference this CWE, most recent first.

GHSA-MGHH-PGCX-3JJJ

Vulnerability from github – Published: 2026-09-30 15:03 – Updated: 2026-09-30 15:03
VLAI
Summary
Axios: ReDoS (O(N²)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location
Details

Summary

Axios shouldBypassProxy() normalizes hostnames with hostname.replace(/\.+$/, ''). For a hostname shaped as many dots followed by a non-dot, the anchored regex can perform quadratic backtracking. Because axios re-evaluates proxy bypass rules for redirected requests, a malicious server can trigger this synchronous work through a crafted redirect Location.

The issue affects Node.js applications that use environment proxy variables with NO_PROXY and allow redirects.

Impact

An attacker-controlled server can return a redirect whose hostname causes the axios process to spend significant CPU time in synchronous hostname normalization. During this time, the Node.js event loop is blocked and the application cannot handle other work on that thread.

This is an availability-only issue. It does not disclose request data or modify requests.

Affected Functionality

Affected:

  • Node.js HTTP adapter.
  • Environment proxy handling through HTTP_PROXY or HTTPS_PROXY.
  • NO_PROXY or no_proxy set to a non-empty value.
  • Redirects followed by axios or follow-redirects.

Not affected:

  • Browser adapters.
  • Requests with proxy: false.
  • Requests with no NO_PROXY value.
  • Requests with maxRedirects: 0, unless application code manually follows the malicious redirect and re-enters axios.

Technical Details

lib/helpers/shouldBypassProxy.js contains:

return unmapIPv4MappedIPv6(hostname.replace(/\.+$/, ''));

When the hostname is "." * n + "a", the $ anchor causes the regex engine to retry the dot run from many positions before it fails. setProxy() invokes shouldBypassProxy(location) after getProxyForUrl(location) returns a proxy, including on redirect hops via beforeRedirects.proxy.

Local timing on axios 1.18.1 showed increasing cost for crafted hostnames: about 1 ms at 1000 dots, 6.9 ms at 3000 dots, and 34.5 ms at 6000 dots. The growth is consistent with the submitted quadratic claim while avoiding long-running payloads.

Proof of Concept of Attack

Constrained helper-level demonstration:

import shouldBypassProxy from 'axios/lib/helpers/shouldBypassProxy.js';

process.env.NO_PROXY = 'example.com';
shouldBypassProxy('http://' + '.'.repeat(6000) + 'a/');

In the full adapter path, a malicious server can return that hostname in a 302 Location header while the client has proxy environment variables and NO_PROXY configured.

Workarounds

Disable automatic redirects for requests to untrusted servers, or avoid environment proxy handling for those requests with proxy: false when appropriate. Operators can also avoid broad untrusted redirect-following in services where event-loop availability is critical.

Original report

### Summary shouldBypassProxy normalizes a host with hostname.replace(/\.+$/, ''). On a host of the shape (e.g. "." × 40000 + "a"), this anchored regex backtracks quadratically (O(N²)), synchronously starving the Node.js event loop. Because axios re-evaluates the proxy on every redirect using the new Location host, a malicious server can return a crafted 302 Location and freeze the client's event loop for seconds per redirect — a denial of service. ### Details - Affected code: lib/helpers/shouldBypassProxy.js → normalizeNoProxyHost: hostname.replace(/\.+$/, '') (one pass in 1.18.1). The open PR #11029 adds a second /\.+$/ pass in normalizeIPAddress, doubling the cost (not the origin). - Root cause: /\.+$/ is O(N²) on a long run of dots that is not at the end of the string — the $ anchor forces the engine to backtrack the entire dot-run from every start position. - Trust boundary (per THREATMODEL): the redirect Location is untrusted (T-2: "axios to network … redirect Location … untrusted"). The caller requests a benign URL; the malicious host arrives via the server's 302. This is not the T-1 caller-supplied-URL non-goal. - Call chain: setProxy(options, configProxy, location, isRedirect, …) (lib/adapters/http.js) → env-proxy branch → getProxyForUrl(location) returns a proxy → if (!shouldBypassProxy(location)) → normalizeNoProxyHost(parsed.hostname.toLowerCase()) runs /\.+$/. setProxy is re-invoked on the redirect hop with the untrusted Location; new URL() retains the long dot-run in .hostname. - Preconditions: proxy configured via environment (HTTP_PROXY/HTTPS_PROXY, trusted per THREATMODEL T-3, common in CI/containers/enterprise) + NO_PROXY set + redirects followed (default maxRedirects: 5). ### PoC Self-contained, no network — imports axios's own helper: // node poc.mjs (run next to an axios install) import sbp from './node_modules/axios/lib/helpers/shouldBypassProxy.js'; process.env.NO_PROXY = 'example.com'; for (const n of [5000, 10000, 20000, 40000]) { const url = 'http://' + '.'.repeat(n) + 'a/'; // arrives as an untrusted 302 Location host const t0 = process.hrtime.bigint(); sbp(url); // returns false (correct no-bypass) — but O(N^2) slow console.log(`N=${n}: ${(Number(process.hrtime.bigint()-t0)/1e6)|0} ms`); } // Measured on 1.18.1: N=5000 ~43ms, 10000 ~160ms, 20000 ~618ms, 40000 ~2499ms; benign host ~0.05ms. Driven through the real http-adapter __setProxy on the redirect path (setProxy(…, isRedirect=true)), a 10 ms timer fires 0 times during the ~2.4 s block at N=40000 — full event-loop starvation. ### Impact Denial of service (event-loop starvation) on any axios client that uses an environment proxy with NO_PROXY set and follows redirects, when a server it contacts returns a crafted redirect Location. No data exposure or RCE. Same impact class as the accepted DoS advisories GHSA-62hf-57xw-28j9 (toFormData recursion) and the maxContentLength response-size DoS. ### Suggested fix Replace the regex trailing-dot strip with a linear trim: let end = hostname.length; while (end > 0 && hostname.charCodeAt(end - 1) === 46 /* '.' */) end--; hostname = hostname.slice(0, end); Also drop the redundant second /\.+$/ pass in PR #11029's normalizeIPAddress.
Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "axios"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "1.15.0"
            },
            {
              "fixed": "1.20.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-101906"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1333",
      "CWE-400"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-09-30T15:03:02Z",
    "nvd_published_at": "2026-09-28T18:17:19Z",
    "severity": "HIGH"
  },
  "details": "## Summary\n\nAxios `shouldBypassProxy()` normalizes hostnames with `hostname.replace(/\\.+$/, \u0027\u0027)`. For a hostname shaped as many dots followed by a non-dot, the anchored regex can perform quadratic backtracking. Because axios re-evaluates proxy bypass rules for redirected requests, a malicious server can trigger this synchronous work through a crafted redirect `Location`.\n\nThe issue affects Node.js applications that use environment proxy variables with `NO_PROXY` and allow redirects.\n\n## Impact\n\nAn attacker-controlled server can return a redirect whose hostname causes the axios process to spend significant CPU time in synchronous hostname normalization. During this time, the Node.js event loop is blocked and the application cannot handle other work on that thread.\n\nThis is an availability-only issue. It does not disclose request data or modify requests.\n\n## Affected Functionality\n\nAffected:\n\n- Node.js HTTP adapter.\n- Environment proxy handling through `HTTP_PROXY` or `HTTPS_PROXY`.\n- `NO_PROXY` or `no_proxy` set to a non-empty value.\n- Redirects followed by axios or `follow-redirects`.\n\nNot affected:\n\n- Browser adapters.\n- Requests with `proxy: false`.\n- Requests with no `NO_PROXY` value.\n- Requests with `maxRedirects: 0`, unless application code manually follows the malicious redirect and re-enters axios.\n\n## Technical Details\n\n`lib/helpers/shouldBypassProxy.js` contains:\n\n```js\nreturn unmapIPv4MappedIPv6(hostname.replace(/\\.+$/, \u0027\u0027));\n```\n\nWhen the hostname is `\".\" * n + \"a\"`, the `$` anchor causes the regex engine to retry the dot run from many positions before it fails. `setProxy()` invokes `shouldBypassProxy(location)` after `getProxyForUrl(location)` returns a proxy, including on redirect hops via `beforeRedirects.proxy`.\n\nLocal timing on axios `1.18.1` showed increasing cost for crafted hostnames: about 1 ms at 1000 dots, 6.9 ms at 3000 dots, and 34.5 ms at 6000 dots. The growth is consistent with the submitted quadratic claim while avoiding long-running payloads.\n\n## Proof of Concept of Attack\n\nConstrained helper-level demonstration:\n\n```js\nimport shouldBypassProxy from \u0027axios/lib/helpers/shouldBypassProxy.js\u0027;\n\nprocess.env.NO_PROXY = \u0027example.com\u0027;\nshouldBypassProxy(\u0027http://\u0027 + \u0027.\u0027.repeat(6000) + \u0027a/\u0027);\n```\n\nIn the full adapter path, a malicious server can return that hostname in a `302 Location` header while the client has proxy environment variables and `NO_PROXY` configured.\n\n## Workarounds\n\nDisable automatic redirects for requests to untrusted servers, or avoid environment proxy handling for those requests with `proxy: false` when appropriate. Operators can also avoid broad untrusted redirect-following in services where event-loop availability is critical.\n\n\u003cdetails\u003e\n  \u003csummary\u003e\u003ch3\u003eOriginal report\u003c/h3\u003e\u003c/summary\u003e\n  \n### Summary\n\nshouldBypassProxy normalizes a host with hostname.replace(/\\.+$/, \u0027\u0027). On a host of the shape \u003cmany dots\u003e\u003cnon-dot\u003e (e.g. \".\" \u00d7 40000 + \"a\"), this anchored regex backtracks quadratically (O(N\u00b2)), synchronously starving the Node.js event loop. Because axios re-evaluates the proxy on every redirect using the new Location host, a malicious server can return a crafted 302 Location and freeze the client\u0027s event loop for seconds per redirect \u2014 a denial of service.\n\n### Details\n\n- Affected code: lib/helpers/shouldBypassProxy.js \u2192 normalizeNoProxyHost: hostname.replace(/\\.+$/, \u0027\u0027) (one pass in 1.18.1). The open PR #11029 adds a second /\\.+$/ pass in normalizeIPAddress, doubling the cost (not the origin).\n- Root cause: /\\.+$/ is O(N\u00b2) on a long run of dots that is not at the end of the string \u2014 the $ anchor forces the engine to backtrack the entire dot-run from every start position.\n- Trust boundary (per THREATMODEL): the redirect Location is untrusted (T-2: \"axios to network \u2026 redirect Location \u2026 untrusted\"). The caller requests a benign URL; the malicious host arrives via the server\u0027s\u00a0302. This is not the T-1 caller-supplied-URL non-goal.\n- Call chain: setProxy(options, configProxy, location, isRedirect, \u2026) (lib/adapters/http.js) \u2192 env-proxy branch \u2192 getProxyForUrl(location) returns a proxy \u2192 if (!shouldBypassProxy(location)) \u2192 normalizeNoProxyHost(parsed.hostname.toLowerCase()) runs /\\.+$/. setProxy is re-invoked on the redirect hop with the untrusted Location; new URL() retains the long dot-run in .hostname.\n- Preconditions: proxy configured via environment (HTTP_PROXY/HTTPS_PROXY, trusted per THREATMODEL T-3, common in CI/containers/enterprise) + NO_PROXY set + redirects followed (default maxRedirects: 5).\n\n### PoC\n\nSelf-contained, no network \u2014 imports axios\u0027s own helper:\n// node poc.mjs   (run next to an axios install)\nimport sbp from \u0027./node_modules/axios/lib/helpers/shouldBypassProxy.js\u0027;\nprocess.env.NO_PROXY = \u0027example.com\u0027;\nfor (const n of [5000, 10000, 20000, 40000]) {\n  const url = \u0027http://\u0027 + \u0027.\u0027.repeat(n) + \u0027a/\u0027;   // arrives as an untrusted 302 Location host\n  const t0 = process.hrtime.bigint();\n  sbp(url);                                         // returns false (correct no-bypass) \u2014 but O(N^2) slow\n  console.log(`N=${n}: ${(Number(process.hrtime.bigint()-t0)/1e6)|0} ms`);\n}\n// Measured on 1.18.1: N=5000 ~43ms, 10000 ~160ms, 20000 ~618ms, 40000 ~2499ms; benign host ~0.05ms.\nDriven through the real http-adapter __setProxy on the redirect path (setProxy(\u2026, isRedirect=true)), a 10 ms timer fires 0 times during the ~2.4 s block at N=40000 \u2014 full event-loop starvation.\n\n### Impact\n\nDenial of service (event-loop starvation) on any axios client that uses an environment proxy with NO_PROXY set and follows redirects, when a server it contacts returns a crafted redirect Location. No data exposure or RCE. Same impact class as the accepted DoS advisories GHSA-62hf-57xw-28j9 (toFormData recursion) and the maxContentLength response-size DoS.\n\n### Suggested fix\n\nReplace the regex trailing-dot strip with a linear trim:\nlet end = hostname.length;\nwhile (end \u003e 0 \u0026\u0026 hostname.charCodeAt(end - 1) === 46 /* \u0027.\u0027 */) end--;\nhostname = hostname.slice(0, end);\nAlso drop the redundant second /\\.+$/ pass in PR #11029\u0027s normalizeIPAddress.\n\u003c/details\u003e\n\n---",
  "id": "GHSA-mghh-pgcx-3jjj",
  "modified": "2026-09-30T15:03:02Z",
  "published": "2026-09-30T15:03:02Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/axios/axios/security/advisories/GHSA-mghh-pgcx-3jjj"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-101906"
    },
    {
      "type": "WEB",
      "url": "https://github.com/axios/axios/pull/11141"
    },
    {
      "type": "WEB",
      "url": "https://github.com/axios/axios/commit/d19040bda7a8be2f82c3c6e1a5bc03917daee39a"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/axios/axios"
    },
    {
      "type": "WEB",
      "url": "https://github.com/axios/axios/releases/tag/v1.20.0"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "Axios: ReDoS (O(N\u00b2)) in shouldBypassProxy host normalization, reachable via untrusted redirect Location"
}

GHSA-MHVH-FQ92-PFMR

Vulnerability from github – Published: 2026-10-02 22:38 – Updated: 2026-10-02 22:38
VLAI
Summary
geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point
Details

Impact

geopy.Point and Point.from_string() may take excessive CPU time when parsing long, malformed coordinate strings due to inefficient regular-expression behavior. The numeric Point constructor is not affected.

Geocoders' reverse methods called with string inputs exercise the vulnerable path.

Applications are affected when they pass attacker-controlled strings to these APIs without an appropriate length limit. Repeated requests may cause denial of service.

Patches

Fixed in geopy 2.5.0 by rejecting overly long (over 256 characters) coordinate strings before parsing.

Workarounds

Limit coordinate strings to a reasonable maximum length, such as 256 characters, before passing them to geopy.

Show details on source website

{
  "affected": [
    {
      "database_specific": {
        "last_known_affected_version_range": "\u003c= 2.4.1"
      },
      "package": {
        "ecosystem": "PyPI",
        "name": "geopy"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2.5.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-77387"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1333"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-10-02T22:38:14Z",
    "nvd_published_at": "2026-10-01T17:17:31Z",
    "severity": "MODERATE"
  },
  "details": "### Impact\n\n`geopy.Point` and `Point.from_string()` may take excessive CPU time when parsing long, malformed coordinate strings due to inefficient regular-expression behavior. The numeric Point constructor is not affected.\n\nGeocoders\u0027 `reverse` methods called with string inputs exercise the vulnerable path.\n\nApplications are affected when they pass attacker-controlled strings to these APIs without an appropriate length limit. Repeated requests may cause denial of service.\n\n### Patches\n\nFixed in geopy **2.5.0** by rejecting overly long (over 256 characters) coordinate strings before parsing.\n\n### Workarounds\n\nLimit coordinate strings to a reasonable maximum length, such as 256 characters, before passing them to geopy.",
  "id": "GHSA-mhvh-fq92-pfmr",
  "modified": "2026-10-02T22:38:14Z",
  "published": "2026-10-02T22:38:14Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/geopy/geopy/security/advisories/GHSA-mhvh-fq92-pfmr"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-77387"
    },
    {
      "type": "WEB",
      "url": "https://github.com/geopy/geopy/issues/608"
    },
    {
      "type": "WEB",
      "url": "https://github.com/geopy/geopy/pull/610"
    },
    {
      "type": "WEB",
      "url": "https://github.com/geopy/geopy/commit/5d09fa843f90ec80788b61552539c9fd3ae6c528"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/geopy/geopy"
    },
    {
      "type": "WEB",
      "url": "https://github.com/geopy/geopy/releases/tag/2.5.0"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
      "type": "CVSS_V3"
    }
  ],
  "summary": "geopy: Regular Expression Denial of Service (ReDoS) in geopy.Point"
}

GHSA-MHWM-JH88-3GJF

Vulnerability from github – Published: 2025-03-03 22:05 – Updated: 2025-11-04 00:32
VLAI
Summary
CGI has Regular Expression Denial of Service (ReDoS) potential in Util#escapeElement
Details

There is a possibility for Regular expression Denial of Service (ReDoS) by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27220. We recommend upgrading the cgi gem.

Details

The regular expression used in CGI::Util#escapeElement is vulnerable to ReDoS. The crafted input could lead to a high CPU consumption.

This vulnerability only affects Ruby 3.1 and 3.2. If you are using these versions, please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later.

Affected versions

cgi gem versions <= 0.3.5, 0.3.6, 0.4.0 and 0.4.1.

Credits

Thanks to svalkanov for discovering this issue. Also thanks to nobu for fixing this vulnerability.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "RubyGems",
        "name": "cgi"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "0.3.5.1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "RubyGems",
        "name": "cgi"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0.3.6"
            },
            {
              "fixed": "0.3.7"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ],
      "versions": [
        "0.3.6"
      ]
    },
    {
      "package": {
        "ecosystem": "RubyGems",
        "name": "cgi"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0.4.0"
            },
            {
              "fixed": "0.4.2"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2025-27220"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1333"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2025-03-03T22:05:08Z",
    "nvd_published_at": "2025-03-04T00:15:31Z",
    "severity": "MODERATE"
  },
  "details": "There is a possibility for Regular expression Denial of Service (ReDoS) by in the cgi gem. This vulnerability has been assigned the CVE identifier CVE-2025-27220. We recommend upgrading the cgi gem.\n\n## Details\n\nThe regular expression used in `CGI::Util#escapeElement` is vulnerable to ReDoS. The crafted input could lead to a high CPU consumption.\n\nThis vulnerability only affects Ruby 3.1 and 3.2. If you are using these versions, please update CGI gem to version 0.3.5.1, 0.3.7, 0.4.2 or later.\n\n## Affected versions\n\ncgi gem versions \u003c= 0.3.5, 0.3.6, 0.4.0 and 0.4.1.\n\n## Credits\n\nThanks to svalkanov for discovering this issue.\nAlso thanks to nobu for fixing this vulnerability.",
  "id": "GHSA-mhwm-jh88-3gjf",
  "modified": "2025-11-04T00:32:21Z",
  "published": "2025-03-03T22:05:08Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-27220"
    },
    {
      "type": "WEB",
      "url": "https://github.com/ruby/cgi/pull/52"
    },
    {
      "type": "WEB",
      "url": "https://github.com/ruby/cgi/pull/53"
    },
    {
      "type": "WEB",
      "url": "https://github.com/ruby/cgi/pull/54"
    },
    {
      "type": "WEB",
      "url": "https://hackerone.com/reports/2890322"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/ruby/cgi"
    },
    {
      "type": "WEB",
      "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/cgi/CVE-2025-27220.yml"
    },
    {
      "type": "WEB",
      "url": "https://lists.debian.org/debian-lts-announce/2025/03/msg00008.html"
    },
    {
      "type": "WEB",
      "url": "https://www.cve.org/CVERecord?id=CVE-2025-27220"
    },
    {
      "type": "WEB",
      "url": "https://www.ruby-lang.org/en/news/2025/02/26/security-advisories"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:L",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "CGI has Regular Expression Denial of Service (ReDoS) potential in Util#escapeElement"
}

GHSA-MMH6-M7V9-5956

Vulnerability from github – Published: 2022-06-03 00:01 – Updated: 2022-06-03 22:25
VLAI
Summary
Regular expression denial of service in markdown-link-extractor
Details

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the markdown-link-extractor npm package, when an attacker is able to supply arbitrary input to the module's exported function

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "markdown-link-extractor"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "3.0.2"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "npm",
        "name": "markdown-link-extractor"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "4.0.0"
            },
            {
              "fixed": "4.0.1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2021-43308"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1333"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2022-06-03T22:25:16Z",
    "nvd_published_at": "2022-06-02T14:15:00Z",
    "severity": "LOW"
  },
  "details": "An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the markdown-link-extractor npm package, when an attacker is able to supply arbitrary input to the module\u0027s exported function",
  "id": "GHSA-mmh6-m7v9-5956",
  "modified": "2022-06-03T22:25:16Z",
  "published": "2022-06-03T00:01:00Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-43308"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/tcort/markdown-link-extractor"
    },
    {
      "type": "WEB",
      "url": "https://research.jfrog.com/vulnerabilities/markdown-link-extractor-redos-xray-211350"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [],
  "summary": "Regular expression denial of service in markdown-link-extractor"
}

GHSA-MMHX-HMJR-R674

Vulnerability from github – Published: 2024-09-16 20:34 – Updated: 2024-09-16 22:37
VLAI
Summary
DOMPurify allows tampering by prototype pollution
Details

It has been discovered that malicious HTML using special nesting techniques can bypass the depth checking added to DOMPurify in recent releases. It was also possible to use Prototype Pollution to weaken the depth check.

This renders dompurify unable to avoid XSS attack.

Fixed by https://github.com/cure53/DOMPurify/commit/1e520262bf4c66b5efda49e2316d6d1246ca7b21 (3.x branch) and https://github.com/cure53/DOMPurify/commit/26e1d69ca7f769f5c558619d644d90dd8bf26ebc (2.x branch).

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "dompurify"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2.5.4"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "npm",
        "name": "dompurify"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "3.0.0"
            },
            {
              "fixed": "3.1.3"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2024-45801"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1321",
      "CWE-1333"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2024-09-16T20:34:26Z",
    "nvd_published_at": "2024-09-16T19:16:11Z",
    "severity": "HIGH"
  },
  "details": "It has been discovered that malicious HTML using special nesting techniques can bypass the depth checking added to DOMPurify in recent releases. It was also possible to use Prototype Pollution to weaken the depth check.\n\nThis renders dompurify unable to avoid XSS attack.\n\nFixed by https://github.com/cure53/DOMPurify/commit/1e520262bf4c66b5efda49e2316d6d1246ca7b21 (3.x branch) and https://github.com/cure53/DOMPurify/commit/26e1d69ca7f769f5c558619d644d90dd8bf26ebc (2.x branch).",
  "id": "GHSA-mmhx-hmjr-r674",
  "modified": "2024-09-16T22:37:33Z",
  "published": "2024-09-16T20:34:26Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/cure53/DOMPurify/security/advisories/GHSA-mmhx-hmjr-r674"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-45801"
    },
    {
      "type": "WEB",
      "url": "https://github.com/cure53/DOMPurify/commit/1e520262bf4c66b5efda49e2316d6d1246ca7b21"
    },
    {
      "type": "WEB",
      "url": "https://github.com/cure53/DOMPurify/commit/26e1d69ca7f769f5c558619d644d90dd8bf26ebc"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/cure53/DOMPurify"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "DOMPurify allows tampering by prototype pollution"
}

GHSA-MMM5-WGVP-WP8R

Vulnerability from github – Published: 2024-09-03 15:30 – Updated: 2025-11-04 00:31
VLAI
Details

There is a MEDIUM severity vulnerability affecting CPython.

Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2024-6232"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1333"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2024-09-03T13:15:05Z",
    "severity": "HIGH"
  },
  "details": "There is a MEDIUM severity vulnerability affecting CPython.\n\n\n\n\n\nRegular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.",
  "id": "GHSA-mmm5-wgvp-wp8r",
  "modified": "2025-11-04T00:31:20Z",
  "published": "2024-09-03T15:30:44Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-6232"
    },
    {
      "type": "WEB",
      "url": "https://github.com/python/cpython/issues/121285"
    },
    {
      "type": "WEB",
      "url": "https://github.com/python/cpython/pull/121286"
    },
    {
      "type": "WEB",
      "url": "https://github.com/python/cpython/commit/34ddb64d088dd7ccc321f6103d23153256caa5d4"
    },
    {
      "type": "WEB",
      "url": "https://github.com/python/cpython/commit/4eaf4891c12589e3c7bdad5f5b076e4c8392dd06"
    },
    {
      "type": "WEB",
      "url": "https://github.com/python/cpython/commit/743acbe872485dc18df4d8ab2dc7895187f062c4"
    },
    {
      "type": "WEB",
      "url": "https://github.com/python/cpython/commit/7d1f50cd92ff7e10a1c15a8f591dde8a6843a64d"
    },
    {
      "type": "WEB",
      "url": "https://github.com/python/cpython/commit/b4225ca91547aa97ed3aca391614afbb255bc877"
    },
    {
      "type": "WEB",
      "url": "https://github.com/python/cpython/commit/d449caf8a179e3b954268b3a88eb9170be3c8fbf"
    },
    {
      "type": "WEB",
      "url": "https://github.com/python/cpython/commit/ed3a49ea734ada357ff4442996fd4ae71d253373"
    },
    {
      "type": "WEB",
      "url": "https://lists.debian.org/debian-lts-announce/2024/12/msg00000.html"
    },
    {
      "type": "WEB",
      "url": "https://mail.python.org/archives/list/security-announce@python.org/thread/JRYFTPRHZRTLMZLWQEUHZSJXNHM4ACTY"
    },
    {
      "type": "WEB",
      "url": "https://security.netapp.com/advisory/ntap-20241018-0007"
    },
    {
      "type": "WEB",
      "url": "http://www.openwall.com/lists/oss-security/2024/09/03/5"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-MMX6-XV2H-W7X8

Vulnerability from github – Published: 2022-05-24 16:56 – Updated: 2024-02-08 21:30
VLAI
Details

The Markdown parser in Zulip server before 2.0.5 used a regular expression vulnerable to exponential backtracking. A user who is logged into the server could send a crafted message causing the server to spend an effectively arbitrary amount of CPU time and stall the processing of future messages.

Show details on source website

{
  "affected": [],
  "aliases": [
    "CVE-2019-16215"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1333"
    ],
    "github_reviewed": false,
    "github_reviewed_at": null,
    "nvd_published_at": "2019-09-18T12:15:00Z",
    "severity": "MODERATE"
  },
  "details": "The Markdown parser in Zulip server before 2.0.5 used a regular expression vulnerable to exponential backtracking. A user who is logged into the server could send a crafted message causing the server to spend an effectively arbitrary amount of CPU time and stall the processing of future messages.",
  "id": "GHSA-mmx6-xv2h-w7x8",
  "modified": "2024-02-08T21:30:32Z",
  "published": "2022-05-24T16:56:27Z",
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2019-16215"
    },
    {
      "type": "WEB",
      "url": "https://github.com/zulip/zulip/commit/5797f013b3be450c146a4141514bda525f2f1b51"
    },
    {
      "type": "WEB",
      "url": "https://blog.zulip.org/2019/09/11/zulip-server-2-0-5-security-release"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ]
}

GHSA-MP6Q-XF9X-FWF7

Vulnerability from github – Published: 2026-02-04 18:02 – Updated: 2026-02-04 21:55
VLAI
Summary
Apollo Serve vulnerable to Denial of Service with `startStandaloneServer`
Details

Impact

The default configuration of startStandaloneServer from @apollo/server/standalone is vulnerable to Denial of Service (DoS) attacks through specially crafted request bodies with exotic character set encodings.

This issue does not affect users that use @apollo/server as a dependency for integration packages, like @as integrations/express5 or @as-integrations/next, only direct usage of startStandaloneServer.

Who is impacted

Users directly using startStandaloneServer from @apollo/server/standalone.

This issue affects Apollo Server from v5.0.0 through v5.3.x.

It also affects all releases of the end-of-life major versions v4, v3, and v2. Although Apollo Server v4 is EOL and Apollo no longer commits to providing support or updates for it, a fix for it was released in v4.13.0. Apollo Server v3 and v2 are no longer updated, as they have been EOL since 2024 and 2023 respectively.

Patches

Patches for this issue are released as @apollo/server versions 5.4.0 and 4.13.0.

In accordance with RFC 7159, these versions now only accept request bodies encoded in UTF-8, UTF-16 (LE or BE), or UTF-32 (LE or BE). Any other character set will be rejected with a 415 Unsupported Media Type error. Note that the more recent JSON RFC, [RFC 8259 (https://datatracker.ietf.org/doc/html/rfc8259#section-8.1), is more strict and will only allow UTF-8. Since this is a minor release, we have chosen to remain compatible with the more permissive RFC 7159 for now. In a future major release, the restriction may be tightened further to only allow UTF-8.

Workarounds

Users of apollo-server v2 or v3 that cannot upgrade for some reason could switch from the standalone apollo-server package to an integration package like apollo-server-express or apollo-server-koa and set up their own server. Please note that these old packages are generally EOL and do not receive any more support or bug fixes. This can only be seen as a short-term workaround. Updating to @apollo/server v5 should be a priority.

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "apollo-server"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "2.0.0"
            },
            {
              "last_affected": "3.13.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "npm",
        "name": "@apollo/server"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "4.2.0"
            },
            {
              "fixed": "4.13.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    },
    {
      "package": {
        "ecosystem": "npm",
        "name": "@apollo/server"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "5.0.0"
            },
            {
              "fixed": "5.4.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2026-23897"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1333"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-02-04T18:02:26Z",
    "nvd_published_at": "2026-02-04T20:16:05Z",
    "severity": "HIGH"
  },
  "details": "### Impact\n\nThe default configuration of `startStandaloneServer` from `@apollo/server/standalone` is vulnerable to Denial of Service (DoS) attacks through specially crafted request bodies with exotic character set encodings.\n\nThis issue does not affect users that use `@apollo/server` as a dependency for integration packages, like `@as integrations/express5` or `@as-integrations/next`, only direct usage of `startStandaloneServer`.\n\n### Who is impacted\n\nUsers directly using `startStandaloneServer` from `@apollo/server/standalone`.\n\nThis issue affects Apollo Server from v5.0.0 through v5.3.x.\n\nIt also affects all releases of the end-of-life major versions v4, v3, and v2.  Although Apollo Server v4 is EOL and Apollo no longer commits to providing support or updates for it, a fix for it was released in v4.13.0.  Apollo Server v3 and v2 are no longer updated, as they have been EOL since 2024 and 2023 respectively.\n\n### Patches\n\nPatches for this issue are released as `@apollo/server` versions `5.4.0` and `4.13.0`.\n\nIn accordance with [RFC 7159](https://datatracker.ietf.org/doc/html/rfc7159#section-8.1), these versions now only accept request bodies encoded in UTF-8, UTF-16 (LE or BE), or UTF-32 (LE or BE). Any other character set will be rejected with a `415 Unsupported Media Type` error. Note that the more recent JSON RFC, [RFC 8259 (https://datatracker.ietf.org/doc/html/rfc8259#section-8.1), is more strict and will only allow UTF-8. Since this is a minor release, we have chosen to remain compatible with the more permissive RFC 7159 for now. In a future major release, the restriction may be tightened further to only allow UTF-8.\n\n### Workarounds\n\nUsers of `apollo-server` v2 or v3 that cannot upgrade for some reason could switch from the standalone `apollo-server`\npackage to an integration package like `apollo-server-express` or `apollo-server-koa` and set up their own server. Please note that these old packages are generally EOL and do not receive any more support or bug fixes. This can only be seen as a short-term workaround. Updating to `@apollo/server` v5 should be a priority.",
  "id": "GHSA-mp6q-xf9x-fwf7",
  "modified": "2026-02-04T21:55:11Z",
  "published": "2026-02-04T18:02:26Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/apollographql/apollo-server/security/advisories/GHSA-mp6q-xf9x-fwf7"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2026-23897"
    },
    {
      "type": "WEB",
      "url": "https://github.com/apollographql/apollo-server/commit/d25a5bdc377826ad424fcf7f8d1d062055911643"
    },
    {
      "type": "WEB",
      "url": "https://github.com/apollographql/apollo-server/commit/e9d49d163a86b8a33be56ed27c494b9acd5400a4"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/apollographql/apollo-server"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    }
  ],
  "summary": "Apollo Serve vulnerable to Denial of Service with `startStandaloneServer`"
}

GHSA-MPG4-RC92-VX8V

Vulnerability from github – Published: 2024-07-29 17:46 – Updated: 2024-10-11 14:13
VLAI
Summary
fast-xml-parser vulnerable to ReDOS at currency parsing
Details

Summary

A ReDOS that exists on currency.js was discovered by Gauss Security Labs R&D team.

Details

https://github.com/NaturalIntelligence/fast-xml-parser/blob/v4.4.0/src/v5/valueParsers/currency.js#L10 contains a vulnerable regex

PoC

pass the following string '\t'.repeat(13337) + '.'

Impact

Denial of service during currency parsing in experimental version 5 of fast-xml-parser-library

https://gauss-security.com

Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "npm",
        "name": "fast-xml-parser"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "4.3.5"
            },
            {
              "fixed": "4.4.1"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2024-41818"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1333",
      "CWE-400"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2024-07-29T17:46:16Z",
    "nvd_published_at": "2024-07-29T16:15:05Z",
    "severity": "HIGH"
  },
  "details": "### Summary\nA ReDOS that exists on currency.js was discovered by Gauss Security Labs R\u0026D team.\n\n### Details\nhttps://github.com/NaturalIntelligence/fast-xml-parser/blob/v4.4.0/src/v5/valueParsers/currency.js#L10 contains a vulnerable regex \n\n### PoC\npass the following string \u0027\\t\u0027.repeat(13337)  + \u0027.\u0027\n\n### Impact\nDenial of service during currency parsing in experimental version 5 of fast-xml-parser-library\n\nhttps://gauss-security.com",
  "id": "GHSA-mpg4-rc92-vx8v",
  "modified": "2024-10-11T14:13:07Z",
  "published": "2024-07-29T17:46:16Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-mpg4-rc92-vx8v"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2024-41818"
    },
    {
      "type": "WEB",
      "url": "https://github.com/NaturalIntelligence/fast-xml-parser/commit/ba5f35e7680468acd7906eaabb2f69e28ed8b2aa"
    },
    {
      "type": "WEB",
      "url": "https://github.com/NaturalIntelligence/fast-xml-parser/commit/d0bfe8a3a2813a185f39591bbef222212d856164"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/NaturalIntelligence/fast-xml-parser"
    },
    {
      "type": "WEB",
      "url": "https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/src/v5/valueParsers/currency.js#L10"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
      "type": "CVSS_V3"
    },
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N",
      "type": "CVSS_V4"
    }
  ],
  "summary": "fast-xml-parser vulnerable to ReDOS at currency parsing"
}

GHSA-MR3Q-G2MV-MR4Q

Vulnerability from github – Published: 2025-10-10 20:28 – Updated: 2025-10-13 15:46
VLAI
Summary
Sinatra is vulnerable to ReDoS through ETag header value generation
Details

Summary

There is a denial of service vulnerability in the If-Match and If-None-Match header parsing component of Sinatra, if the etag method is used when constructing the response and you are using Ruby < 3.2.

Details

Carefully crafted input can cause If-Match and If-None-Match header parsing in Sinatra to take an unexpected amount of time, possibly resulting in a denial of service attack vector. This header is typically involved in generating the ETag header value. Any applications that use the etag method when generating a response are impacted if they are using Ruby below version 3.2.

Resources

  • https://github.com/sinatra/sinatra/issues/2120 (report)
  • https://github.com/sinatra/sinatra/pull/2121 (fix)
  • https://github.com/sinatra/sinatra/pull/1823 (older ReDoS vulnerability)
  • https://bugs.ruby-lang.org/issues/19104 (fix in Ruby >= 3.2)
Show details on source website

{
  "affected": [
    {
      "package": {
        "ecosystem": "RubyGems",
        "name": "sinatra"
      },
      "ranges": [
        {
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "4.2.0"
            }
          ],
          "type": "ECOSYSTEM"
        }
      ]
    }
  ],
  "aliases": [
    "CVE-2025-61921"
  ],
  "database_specific": {
    "cwe_ids": [
      "CWE-1333",
      "CWE-400"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2025-10-10T20:28:47Z",
    "nvd_published_at": "2025-10-10T20:15:38Z",
    "severity": "LOW"
  },
  "details": "### Summary\n\nThere is a denial of service vulnerability in the `If-Match` and `If-None-Match` header parsing component of Sinatra, if the `etag` method is used when constructing the response and you are using Ruby \u003c 3.2.\n\n### Details\n\nCarefully crafted input can cause `If-Match` and `If-None-Match` header parsing in Sinatra to take an unexpected amount of time, possibly resulting in a denial of service attack vector. This header is typically involved in generating the `ETag` header value. Any applications that use the `etag` method when generating a response are impacted if they are using Ruby below version 3.2.\n\n### Resources\n\n* https://github.com/sinatra/sinatra/issues/2120 (report)\n* https://github.com/sinatra/sinatra/pull/2121 (fix)\n* https://github.com/sinatra/sinatra/pull/1823 (older ReDoS vulnerability)\n* https://bugs.ruby-lang.org/issues/19104 (fix in Ruby \u003e= 3.2)",
  "id": "GHSA-mr3q-g2mv-mr4q",
  "modified": "2025-10-13T15:46:28Z",
  "published": "2025-10-10T20:28:47Z",
  "references": [
    {
      "type": "WEB",
      "url": "https://github.com/sinatra/sinatra/security/advisories/GHSA-mr3q-g2mv-mr4q"
    },
    {
      "type": "ADVISORY",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2025-61921"
    },
    {
      "type": "WEB",
      "url": "https://github.com/sinatra/sinatra/issues/2120"
    },
    {
      "type": "WEB",
      "url": "https://github.com/sinatra/sinatra/pull/1823"
    },
    {
      "type": "WEB",
      "url": "https://github.com/sinatra/sinatra/pull/2121"
    },
    {
      "type": "WEB",
      "url": "https://github.com/sinatra/sinatra/commit/3fe8c38dc405586f7ad8f2ac748aa53e9c3615bd"
    },
    {
      "type": "WEB",
      "url": "https://github.com/sinatra/sinatra/commit/8ff496bd4877520599e1479d6efead39304edceb"
    },
    {
      "type": "WEB",
      "url": "https://bugs.ruby-lang.org/issues/19104"
    },
    {
      "type": "WEB",
      "url": "https://github.com/rubysec/ruby-advisory-db/blob/master/gems/sinatra/CVE-2025-61921.yml"
    },
    {
      "type": "PACKAGE",
      "url": "https://github.com/sinatra/sinatra"
    }
  ],
  "schema_version": "1.4.0",
  "severity": [
    {
      "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:U",
      "type": "CVSS_V4"
    }
  ],
  "summary": "Sinatra is vulnerable to ReDoS through ETag header value generation"
}

Mitigation
Architecture and Design

Use regular expressions that do not support backtracking, e.g. by removing nested quantifiers.

Mitigation
System Configuration

Set backtracking limits in the configuration of the regular expression implementation, such as PHP's pcre.backtrack_limit. Also consider limits on execution time for the process.

Mitigation
Implementation

Do not use regular expressions with untrusted input. If regular expressions must be used, avoid using backtracking in the expression.

Mitigation
Implementation

Limit the length of the input that the regular expression will process.

CAPEC-492: Regular Expression Exponential Blowup

An adversary may execute an attack on a program that uses a poor Regular Expression(Regex) implementation by choosing input that results in an extreme situation for the Regex. A typical extreme situation operates at exponential time compared to the input size. This is due to most implementations using a Nondeterministic Finite Automaton(NFA) state machine to be built by the Regex algorithm since NFA allows backtracking and thus more complex regular expressions.