Executive brief
dat.gui is a popular JavaScript GUI library used to create interactive controls for web applications. A regular expression denial of service (ReDoS) vulnerability in the color parsing functionality allows an attacker to send specially crafted RGB/RGBA color strings that cause the application to hang or crash, disrupting availability for all users.
Technical details
The vulnerability is a ReDoS flaw in the regular expression used to parse RGB and RGBA color values in dat/color/interpret.js. The vulnerable patterns (/^rgb\(\s*(.+)\s*,\s*(.+)\s*,\s*(.+)\s*\)/ and the RGBA variant) use nested quantifiers (.+) preceded and followed by \s*, which exhibit catastrophic backtracking on certain inputs. An attacker can trigger this by providing a specially crafted color string—such as "rgb(" followed by thousands of spaces—causing the regex engine to consume excessive CPU and hang the application. No authentication is required; the vulnerability is triggered through normal color-parsing functionality exposed to network input.
Affected products
- dat.gui dat.gui 0 to 0.7.7
Timeline
- 2020-10-06: disclosed: Vulnerability disclosed on GitHub issue #278
- 2021-05-10: advisory: GHSA-chwr-hf3w-c984 published