Junglewise Threat Intelligence

CVE-2017-16099: no-case regular expression denial of service

CVE-2017-16099 · Severity: low · CVSS 3 · Published 2018-07-24

Vendors: npm.

Executive brief

The no-case JavaScript library, commonly used to transform text case in web applications and backend services, contains a vulnerability in its regular expression pattern matching. An attacker who can supply untrusted input to the library can cause the regex engine to hang or consume excessive CPU, leading to application slowdown or complete unavailability.

Technical details

The no-case library is vulnerable to ReDoS (Regular Expression Denial of Service) due to a poorly constructed regular expression pattern used during string parsing. The vulnerability affects all versions prior to 2.3.2 and can be triggered by supplying specially crafted input strings that cause catastrophic backtracking in the regex engine. This is a network-reachable vulnerability with no authentication required if the affected library is exposed through a web service. An attacker can achieve denial of service by exhausting CPU resources, making the application unresponsive. The fix is available in version 2.3.2 and later.

Affected products

  • Blake Embrey no-case before 2.3.2

Timeline

  • 2018-07-24: disclosed

References