Executive brief
The braces library is a Node.js utility used to expand brace patterns in strings (e.g., converting {1..3} to 1, 2, 3). A flaw in its regex handling allows an attacker to craft malicious input that causes the parser to hang or consume excessive CPU, leading to denial of service in any application using this library.
Technical details
A Regular Expression Denial of Service (ReDoS) vulnerability exists in the braces package versions 2.2.0 through 2.3.0 due to a vulnerable regex pattern in the multiplier parser. The flaw is in lib/parsers.js, where a complex regex exhibits catastrophic backtracking when processing specially crafted brace patterns. An attacker can supply input strings containing nested or repeated brace sequences that trigger exponential regex evaluation, causing the application to hang or consume excessive CPU. The vulnerability was patched in version 2.3.1 by optimizing the regex pattern to eliminate backtracking.
Affected products
- micromatch braces 2.2.0 through 2.3.0
Timeline
- 2022-01-06: disclosed
- 2.3.1: patched