Executive brief
The charset Node.js library is vulnerable to a regular expression denial of service (ReDoS) attack in its HTTP header parsing logic. An attacker can send a specially crafted request with a malicious input that causes the parser to hang or consume excessive CPU, potentially disrupting service availability. This is particularly severe in Node.js applications that have configured a large HTTP header size limit.
Technical details
The vulnerability is a regular expression denial of service (CWE-400) affecting the charset library's HTTP header parsing regex. The vulnerable pattern uses nested quantifiers in a character set and encoding matcher, making it susceptible to catastrophic backtracking. An attacker can craft a malicious HTTP header approximately 50,000 characters in length to trigger 2+ seconds of processing time; impact is amplified on systems with custom HTTP_MAX_HEADER_SIZE configurations. The attack requires only network access and no authentication. The vulnerability is fixed in version 1.0.1 and later.
Affected products
- npm charset before 1.0.1
Timeline
- 2017-09-05: disclosed: Vulnerability reported on GitHub
- 2018-08-09: patched: Fix released in version 1.0.1