Executive brief
websocket-extensions is a Node.js library that parses WebSocket protocol headers. A flaw in its regular expression parser allows an attacker to send a specially crafted WebSocket handshake request that consumes exponential CPU time, blocking the server from processing other requests and potentially rendering the entire service unavailable.
Technical details
The vulnerability is a Regular Expression Denial of Service (ReDoS) in the Sec-WebSocket-Extensions header parser. The flaw is triggered by a malformed header containing an unclosed string parameter with a repeating two-byte pattern (backslash followed by any character), which causes the regex engine to exhibit catastrophic backtracking. An unauthenticated attacker can send this specially crafted header during the WebSocket handshake phase (network-accessible, no authentication required). The parser takes exponential time to reject the header as invalid, blocking all other work on the same server thread; on single-threaded servers this results in complete denial of service. The vulnerability was patched in version 0.1.4.
Affected products
- Faye websocket-extensions < 0.1.4
Timeline
- 2020-06-02: disclosed
- 2020-06-03: patched: version 0.1.4 released