Executive brief
bleach is a JavaScript library used to sanitize HTML content in web applications. A regular expression denial of service (ReDoS) vulnerability allows attackers to cause application unavailability by crafting specially formatted HTML input, potentially disrupting services that rely on this sanitization module.
Technical details
This is a regular expression denial of service (ReDoS) vulnerability in bleach's HTML sanitization function. The vulnerability stems from the library's use of inefficiently designed regular expressions to parse HTML without limiting input length, making it susceptible to catastrophic backtracking. An attacker can exploit this by sending crafted HTML input to any application using the sanitize function, causing excessive CPU consumption and rendering the service unavailable. No special privileges or user interaction are required—the attack is remotely exploitable over the network. The bleach package is no longer maintained (last update in 2014), and the vulnerability affects all versions. Migration to an actively maintained alternative HTML sanitization library is the recommended mitigation.
Affected products
- bleach bleach all versions up to 3.0
Timeline
- 2015-10-24: disclosed: Vulnerability disclosed to npm advisor
- 2020-09-01: advisory: GHSA-mvmf-cvfx-qg55 published