Junglewise Threat Intelligence

asymmetric-effort nogginlessdom ReDoS in HTMLInputElement pattern validation

Severity: medium · CVSS 6.9 · Published 2026-07-02

Technologies: @asymmetric-effort/nogginlessdom (npm), Asymmetric Effort Nogginlessdom. Vendors: npm, Asymmetric Effort.

Executive brief

A vulnerability exists in the NogginLessDom library, which is used for simulating web browser environments in Node.js. An attacker can provide a specially crafted text pattern that causes the system to freeze or become unresponsive when validating input fields. This could lead to a denial-of-service, impacting the availability of applications relying on this library for DOM simulation.

Technical details

The vulnerability is a Regular Expression Denial of Service (ReDoS) classified as CWE-1333. The `HTMLInputElement.checkValidity()` method in NogginLessDom constructed a `RegExp` object directly from the `pattern` attribute without sanitization or execution timeouts. By providing a pattern with nested quantifiers (e.g., `(a+)+`), an attacker can trigger catastrophic backtracking during validation, consuming excessive CPU and blocking the event loop. The issue is fixed in version 0.0.22 by implementing a 1024-character pattern length limit and a `hasNestedQuantifiers` check to reject dangerous regex structures.

Affected products

  • asymmetric-effort nogginlessdom <= 0.0.21

Timeline

  • 2026-05-29: disclosed: Advisory published by maintainer
  • 2026-05-29: patched: Fixed in version 0.0.22 via commit 25a3cba
  • 2026-07-02: advisory: GitHub Advisory Database entry reviewed and published

References

Related threats