Junglewise Threat Intelligence

CVE-2015-8855: Node.js semver Regular Expression Denial of Service

CVE-2015-8855 · Severity: high · CVSS 7.5 · Published 2017-01-23

Technologies: Nodejs Node.Js. Vendors: Nodejs.

Executive brief

The semver library, a widely used tool for managing software versioning in Node.js applications, is vulnerable to a denial-of-service attack. By providing a specially crafted, long version string, an attacker can cause the application to consume excessive CPU resources. This can lead to application slowdowns or complete service outages, preventing legitimate users from accessing the system.

Technical details

The semver package prior to version 4.3.2 contains a Regular Expression Denial of Service (ReDoS) vulnerability. The issue resides in the regular expressions used to parse and validate version strings; when processed against specifically crafted, excessively long input strings, the regex engine experiences catastrophic backtracking. This results in 100% CPU utilization for the affected Node.js event loop thread. The attack can be launched remotely without authentication if the application accepts user-supplied version strings for comparison or validation. The vulnerability is resolved in version 4.3.2.

Affected products

  • Node.js semver < 4.3.2

Timeline

  • 2015-08-03: disclosed: Internal disclosure via Node Security Project (approximate based on CVE year)
  • 2017-01-23: advisory: NVD publication date

References

Related threats