Junglewise Threat Intelligence

CVE-2020-26256: fast-csv ReDoS in ignoreEmpty option

CVE-2020-26256 · Severity: low · CVSS 3.1 · Published 2020-12-08

Vendors: npm.

Executive brief

fast-csv is a popular Node.js library for parsing and formatting CSV files. A regular expression denial-of-service (ReDoS) vulnerability in the ignoreEmpty parsing option allows an attacker to cause excessive CPU consumption by sending specially crafted CSV input, potentially disrupting application availability.

Technical details

The vulnerability is a regular expression denial-of-service (ReDoS) issue affecting the EMPTY_ROW_REGEXP regular expression used when the ignoreEmpty option is enabled during CSV parsing. An attacker with the ability to supply malicious CSV input can craft a payload that triggers catastrophic backtracking in the regex engine, causing CPU exhaustion. This vulnerability requires the application to be configured with the ignoreEmpty option enabled and to process untrusted CSV data. The vulnerability has been patched in version 4.3.6.

Affected products

  • C2FO fast-csv < 4.3.6
  • C2FO @fast-csv/parse < 4.3.6

Timeline

  • 2020-12-08: disclosed
  • 2020-12-08: patched: Version 4.3.6 released

References