Executive brief
The urlregex library is a JavaScript package used to validate and parse URLs. A maliciously crafted long URL string can cause the regex engine to consume excessive CPU resources through catastrophic backtracking, leading to denial of service. Applications using older versions of urlregex may experience service degradation or crashes when processing untrusted URL input.
Technical details
The vulnerability is a ReDoS (Regular Expression Denial of Service) flaw in the regular expression used by urlregex's URL validation logic in index.js. The regex pattern is susceptible to catastrophic backtracking when processing certain input strings, allowing an attacker to craft a malicious URL that triggers exponential backtracking behavior. An attacker on the network can send specially crafted URLs to any service using vulnerable versions of urlregex; no authentication is required. Successful exploitation causes the service to hang or become unresponsive due to CPU exhaustion. The fix, released in version 0.5.1, replaces the backtracking-prone regex engine with Google's RE2 library, which does not suffer from catastrophic backtracking.
Affected products
- nescalante urlregex versions before 0.5.1
Timeline
- 2024-09-02: disclosed: Vulnerability published to GitHub Advisory Database
- 2020-09-16: patched: Security fix merged in pull request #8; version 0.5.1 released with RE2 engine replacement