Executive brief
protobufjs is a widely-used JavaScript library for parsing and serializing Protocol Buffer messages. Versions before 5.0.3 and 6.8.6 are vulnerable to a denial-of-service attack when processing specially crafted invalid .proto files. An attacker can craft a malicious .proto file that causes the parser's regular expression engine to hang or consume excessive CPU, disrupting applications that depend on this library.
Technical details
This vulnerability is a regular expression denial of service (ReDoS) in protobufjs's .proto file parser. The vulnerable code uses a regular expression in the parse module that exhibits catastrophic backtracking when processing crafted invalid input. The attack is triggered locally via a malicious .proto file (user interaction required—the file must be parsed). Successful exploitation causes CPU exhaustion and service disruption. Patches are available: update to version 5.0.3, 6.8.6, or later to remove the vulnerable regex pattern.
Affected products
- protobufjs protobufjs before 5.0.3 and 6.0.0 before 6.8.6
Timeline
- 2018-06-07: disclosed
- 2018-10-09: advisory
- 2018-10-09: patched: versions 5.0.3 and 6.8.6 released