Junglewise Threat Intelligence

CVE-2021-23362: npm hosted-git-info regular expression denial of service

CVE-2021-23362 · Severity: low · CVSS 3.1 · Published 2021-05-06

Vendors: npm.

Executive brief

The hosted-git-info npm package is a widely-used library that parses and converts Git repository URLs. Versions before 2.8.9 and 3.0.0–3.0.7 contain a regular expression flaw that can be exploited to cause a denial of service, where a specially crafted repository URL forces the library to consume excessive CPU resources, potentially disrupting any application that depends on it.

Technical details

The vulnerability is a Regular Expression Denial of Service (ReDoS) flaw (CWE-400) in the shortcutMatch regular expression within the fromUrl function in index.js. The vulnerable regex exhibits polynomial worst-case time complexity when processing specially crafted input strings. An attacker can supply a malicious Git repository URL to any application using hosted-git-info; no authentication or user interaction is required. When the library attempts to parse the URL, the regex engine enters catastrophic backtracking, consuming excessive CPU and causing the application to hang or become unresponsive. The fix, released in versions 2.8.9 and 3.0.8, simplifies the regular expression to remove the complexity that enables the ReDoS attack. Patches are available via npm update.

Affected products

  • npm hosted-git-info All versions before 2.8.9 and versions 3.0.0 through 3.0.7

Timeline

  • 2021-03-23: disclosed: NVD published CVE-2021-23362
  • 2021-05-06: advisory: GHSA-43f8-2h32-f4cj advisory published
  • 2021-01-28: patched: Pull request #76 merged with simplified regex

References