Junglewise Threat Intelligence

CVE-2017-16113: parsejson regular expression denial of service

CVE-2017-16113 · Severity: info · CVSS 7.5 · Published 2018-07-24

Vendors: npm.

Executive brief

parsejson is a Node.js library for parsing JSON data. When parsing untrusted user input, the library is vulnerable to a regular expression denial of service (ReDoS) attack that can cause the application to hang or consume excessive CPU resources, disrupting service availability.

Technical details

The vulnerability is a regular expression denial of service (ReDoS / CWE-400) affecting all versions of the parsejson library through 0.0.3. When parsing untrusted or maliciously crafted JSON input, an attacker can trigger exponential backtracking in the library's regex patterns, causing the parser to consume excessive CPU and memory. The attack vector is network-accessible if the application accepts JSON from external sources. The advisory recommends using Node.js's native JSON.parse() function instead, which is both faster and secure.

Affected products

  • parsejson parsejson 0.0.3 and earlier

Timeline

  • 2018-07-24: disclosed
  • 2017: other: CVE-2017-16113 assigned

References