Executive brief
parsejson is a Node.js library for parsing JSON data. When parsing untrusted user input, the library is vulnerable to a regular expression denial of service (ReDoS) attack that can cause the application to hang or consume excessive CPU resources, disrupting service availability.
Technical details
The vulnerability is a regular expression denial of service (ReDoS / CWE-400) affecting all versions of the parsejson library through 0.0.3. When parsing untrusted or maliciously crafted JSON input, an attacker can trigger exponential backtracking in the library's regex patterns, causing the parser to consume excessive CPU and memory. The attack vector is network-accessible if the application accepts JSON from external sources. The advisory recommends using Node.js's native JSON.parse() function instead, which is both faster and secure.
Affected products
- parsejson parsejson 0.0.3 and earlier
Timeline
- 2018-07-24: disclosed
- 2017: other: CVE-2017-16113 assigned