Executive brief
The 'trim-off-newlines' library is a utility used by developers to remove newline characters from the beginning and end of text strings. A security flaw in this library allows an attacker to provide specially crafted text that causes the system to consume excessive processor resources. This can lead to a 'Denial of Service' (DoS), where the application becomes slow or unresponsive, potentially disrupting business operations and service availability.
Technical details
The 'trim-off-newlines' package is vulnerable to Regular Expression Denial of Service (ReDoS) due to an inefficient regular expression used for string processing. An attacker can exploit this by providing a long string with a specific pattern of newline characters (e.g., repeated '\r\n' sequences), triggering 'catastrophic backtracking' in the JavaScript regex engine. This results in exponential CPU consumption for a single request, allowing a remote, unauthenticated attacker to cause a denial-of-service condition. The vulnerability is fixed in version 1.0.3 by updating the regular expression to a more efficient pattern.
Affected products
- stevemao trim-off-newlines < 1.0.3
Timeline
- 2021-05-26: disclosed: Vulnerability disclosed to Snyk
- 2021-08-18: advisory: NVD and Snyk published advisories
- 2021-09-17: patched: Fix merged into master branch and released in version 1.0.3