Junglewise Threat Intelligence

CVE-2020-7760: CodeMirror regular expression denial of service

CVE-2020-7760 · Severity: low · CVSS 3.1 · Published 2021-05-10

Vendors: npm, Apache.

Executive brief

CodeMirror is a popular JavaScript-based code editor used in web applications and development tools. A flaw in its JavaScript mode regular expression can cause the editor to consume excessive CPU resources when processing specially crafted input, potentially making the application unresponsive or slow to users. This denial-of-service condition can be triggered by attackers who can supply input to the editor.

Technical details

The vulnerability is a Regular Expression Denial of Service (ReDoS) in the JavaScript syntax highlighter mode of CodeMirror. The vulnerable regular expression is located in mode/javascript/javascript.js at line 129 and contains a problematic sub-pattern (\s|/\*.*?\*/)* that can cause catastrophic backtracking when processing malicious input. The pattern attempts to match whitespace or C-style block comments but lacks proper atomic grouping or possessive quantifiers, allowing the regex engine to explore exponentially many possible backtracking paths. An attacker can craft input (e.g., a deeply nested sequence of comment delimiters followed by a non-matching character) that causes the regex engine to consume excessive CPU cycles, degrading application performance. The fix, applied in commit 55d0333, replaces the vulnerable pattern with (\s|/\*([^*]|\*(?!\/))*?\*/)* to prevent catastrophic backtracking. Patches are available in codemirror 5.58.2 and later versions across multiple package distributions (npm, Maven/WebJars, etc.).

Affected products

  • CodeMirror CodeMirror before 5.58.2
  • Apache Marmotta WebJars codemirror before 5.58.2
  • WebJars codemirror before 5.62.2

Timeline

  • 2020-10-09: disclosed: Vulnerability disclosure by Yeting Li
  • 2020-10-30: other: NVD published CVE-2020-7760
  • 2020: patched: Fix applied in CodeMirror commit 55d0333; version 5.58.2+ released
  • 2021-05-10: advisory: GitHub advisory GHSA-4gw3-8f77-f72c published

References