Executive brief
A vulnerability exists in the NogginLessDom library, which is used for simulating web browser environments in Node.js. An attacker can provide a specially crafted text pattern that causes the system to freeze or become unresponsive when validating input fields. This could lead to a denial-of-service, impacting the availability of applications relying on this library for DOM simulation.
Technical details
The vulnerability is a Regular Expression Denial of Service (ReDoS) classified as CWE-1333. The `HTMLInputElement.checkValidity()` method in NogginLessDom constructed a `RegExp` object directly from the `pattern` attribute without sanitization or execution timeouts. By providing a pattern with nested quantifiers (e.g., `(a+)+`), an attacker can trigger catastrophic backtracking during validation, consuming excessive CPU and blocking the event loop. The issue is fixed in version 0.0.22 by implementing a 1024-character pattern length limit and a `hasNestedQuantifiers` check to reject dangerous regex structures.
Affected products
- asymmetric-effort nogginlessdom <= 0.0.21
Timeline
- 2026-05-29: disclosed: Advisory published by maintainer
- 2026-05-29: patched: Fixed in version 0.0.22 via commit 25a3cba
- 2026-07-02: advisory: GitHub Advisory Database entry reviewed and published