Executive brief
npm-user-validate is a Node.js library used to validate npm user account details such as email addresses. The library contains a flaw in its email validation regex that can be exploited to cause a denial of service: an attacker sending a specially crafted email string (starting with @ and very long) causes the validation function to consume excessive CPU resources, potentially rendering the application unresponsive.
Technical details
The vulnerability is a Regular Expression Denial of Service (ReDoS) in the email validation regex. The regex exhibits exponential backtracking when processing long input strings beginning with @ characters, causing the validation function to take exponentially longer to complete. The attack requires no authentication and is triggered when arbitrary user input is passed to the email validation function without character length limits. An attacker can cause denial of service by submitting a long string with @ prefix to trigger expensive regex processing. The vulnerability is fixed in version 1.0.1, which improves the regex pattern and enforces a 254-character limit on input.
Affected products
- npm npm-user-validate before 1.0.1
Timeline
- 2020-10-16: disclosed
- 2020-10-27: patched: Version 1.0.1 released
- 2021-05-10: advisory