Junglewise Threat Intelligence

CVE-2020-26308: validate.js Regular Expression Denial of Service

CVE-2020-26308 · Severity: medium · CVSS 4 · Published 2024-10-26

Vendors: npm.

Executive brief

validate.js is a JavaScript library that validates objects against declarative rules. A regular expression vulnerability in the library can be exploited to cause a denial of service, where a malicious input triggers excessive CPU consumption and makes the validation function unresponsive, potentially impacting any application relying on this library for input validation.

Technical details

The vulnerability is a Regular Expression Denial of Service (ReDoS) flaw in one or more regular expressions used by validate.js for validation rules (CWE-1333). The vulnerable patterns are susceptible to catastrophic backtracking when given specially crafted input, allowing an attacker to cause CPU exhaustion and service disruption. An attacker can exploit this by providing malicious input to a validation function that uses an affected pattern. No patches are available as of the advisory publication date. The library versions 0.13.1 and earlier are affected, and the project was archived on December 12, 2021 with no further development planned.

Affected products

  • validate.js validate.js 0.13.1 and earlier

Timeline

  • 2024-10-26: disclosed: Vulnerability advisory published
  • 2020-11-30: advisory: GitHub Security Lab team reported vulnerability via issue #342
  • 2021-12-12: other: Repository archived by owner, no further development

References