Executive brief
Handlebars is a popular templating engine used to dynamically generate HTML and other content in web applications. A flaw in its template parsing logic allows attackers to submit malicious templates that cause the parser to enter an infinite loop, consuming CPU resources and rendering the application unavailable to legitimate users. This vulnerability could be exploited remotely without authentication, making it a significant operational risk for services using vulnerable versions.
Technical details
The vulnerability is a Regular Expression Denial of Service (ReDoS) caused by eager matching in Handlebars' raw block content parsing logic (versions 4.0.0 through 4.4.4). The parser uses a greedy regular expression that, when processing crafted templates containing multiple raw blocks of the same kind, may experience catastrophic backtracking. An attacker can submit a specially-crafted template that forces the regex engine to perform exponential amounts of backtracking steps, consuming excessive CPU and causing availability issues. The vulnerability is remotely exploitable with no authentication or user interaction required beyond providing the malicious template to the vulnerable Handlebars instance. A fix was released in version 4.4.5, which changes the regex matching from eager to non-eager mode to prevent the excessive backtracking.
Affected products
- Handlebars Handlebars >=4.0.0, <4.4.5
Timeline
- 2019-10-30: disclosed
- 2019: patched: Version 4.4.5 released with fix
- 2022-02-10: advisory: GitHub Security Advisory published