Junglewise Threat Intelligence

braces regular expression denial of service

Severity: low · CVSS 3.1 · Published 2019-06-06

Technologies: braces (npm). Vendors: npm.

Executive brief

braces is a JavaScript library for Bash-like brace expansion commonly used in build tools and file pattern matching. Versions before 2.3.1 contain a flaw in regular expression parsing that allows an attacker to send specially crafted input causing excessive CPU consumption and application hang, resulting in service unavailability.

Technical details

The vulnerability is a Regular Expression Denial of Service (ReDoS) affecting the regex pattern used to detect empty braces: ^\{(,+(?:(\{,+\})*),*|,*(?:(\{,+\})*),+)\}. The vulnerable component is the parser library's regex matching logic. An attacker can exploit this via network if the application processes untrusted brace expansion patterns, causing catastrophic backtracking in the regex engine—testing shows ~10 seconds of CPU consumption for 50KB of crafted input. No authentication is required. The fix was released in version 2.3.1, which optimizes the regex pattern to prevent backtracking.

Affected products

  • braces braces <2.3.1

Timeline

  • 2018-02-19: disclosed
  • 2018-02-18: patched: Version 2.3.1 released with regex optimization fix

References

Related threats