Junglewise Threat Intelligence

CVE-2017-16021: garycourt uri-js ReDoS in parse method

CVE-2017-16021 · Severity: low · CVSS 3.1 · Published 2018-07-24

Technologies: uri-js (npm). Vendors: npm.

Executive brief

The uri-js library, a popular tool for parsing and validating web addresses (URLs) in JavaScript applications, is vulnerable to a denial-of-service attack. An attacker can provide a specially crafted, long URL that causes the application to consume 100% of its processor power indefinitely. This can lead to the application becoming unresponsive, potentially crashing the service and disrupting business operations.

Technical details

The uri-js library (versions prior to 3.0.0) contains a Regular Expression Denial of Service (ReDoS) vulnerability within its URL validation logic. The root cause is an inefficiently constructed regular expression used in the .parse() method to implement RFC 3986 compliance. When a specifically crafted long string (e.g., a URL with many repeated path segments) is passed to this method, the regex engine experiences exponential backtracking, leading to 100% CPU utilization and a process hang. This is reachable by any network attacker who can influence the input to the parse function. The issue is fixed in version 3.0.0.

Affected products

  • garycourt uri-js < 3.0.0

Timeline

  • 2017-09-13: disclosed: Issue reported on GitHub repository
  • 2018-06-04: advisory: NVD published CVE-2017-16021
  • 2018-07-24: advisory: GitHub Advisory published

References