Junglewise Threat Intelligence

CVE-2020-7779: djvalidator regular expression denial of service

CVE-2020-7779 · Severity: low · CVSS 3.1 · Published 2022-02-09

Vendors: npm.

Executive brief

djvalidator is a jQuery plugin used to validate web forms on client-side applications. A flaw in its email validation logic allows attackers to send specially crafted invalid email addresses that cause the browser or server to consume excessive CPU resources through catastrophic regex backtracking, temporarily disabling the application's form validation and potentially impacting availability.

Technical details

The vulnerability is a Regular Expression Denial of Service (ReDoS) flaw in djvalidator's email validation regex. The vulnerable pattern uses nested quantifiers that exhibit catastrophic backtracking when processed against crafted invalid emails (e.g., --@------------------------------------------------------------------------------------------------------------------------!). An attacker can trigger exponential processing time by providing malicious input; for example, a 14-character string can force over 65,000 regex matching steps. The attack is network-accessible via any web form using the vulnerable library, requires no authentication or user interaction, and causes denial of service by exhausting CPU resources. No patch is available for djvalidator as of the advisory date; all versions up to 1.1.1 are affected.

Affected products

  • djvalidator djvalidator All versions up to 1.1.1

Timeline

  • 2020-10-15: disclosed: Vulnerability disclosed to Snyk
  • 2020-11-26: advisory: Published to NVD
  • 2022-02-09: advisory: Published to GitHub Security Advisory

References