Executive brief
The forwarded npm library is used to parse HTTP forwarding headers in Node.js applications. A vulnerability in the library's regular expression parsing logic allows attackers to craft malicious user input that causes the application to consume excessive CPU resources, resulting in a denial of service attack that can impact application availability.
Technical details
The vulnerability is a regular expression denial of service (ReDoS) flaw in the forwarded library's header parsing logic (CWE-400). When the library processes specially crafted user input in forwarding headers, an inefficient regular expression can cause catastrophic backtracking, consuming excessive CPU resources. The attack requires no authentication or user interaction and is exploitable over the network by sending malicious HTTP headers. An attacker can cause the affected application to become unresponsive or slow significantly. The vulnerability is patched in version 0.1.2 and later.
Affected products
- npm forwarded < 0.1.2
Timeline
- 2018-07-24: disclosed: Published to GitHub Advisory Database
- 2018-07-24: patched: Version 0.1.2 released with fix