Junglewise Threat Intelligence

CVE-2021-23446: Handsontable regular expression denial of service in isNumeric

CVE-2021-23446 · Severity: low · CVSS 3.1 · Published 2021-09-30

Vendors: npm.

Executive brief

Handsontable is a popular JavaScript data table library used in web applications to display and edit spreadsheet-like data. The library contains an inefficient regular expression in its numeric validation function that can be exploited to cause a denial of service by consuming excessive CPU, making the application unresponsive when processing malicious input.

Technical details

The vulnerability is a Regular Expression Denial of Service (ReDoS) in the Handsontable.helper.isNumeric function, caused by inefficient regex pattern matching (CWE-1333). An attacker can provide specially crafted input strings that trigger catastrophic backtracking in the regular expression engine, leading to exponential time complexity and CPU exhaustion. The vulnerability affects all versions before 10.0.0 and is reachable via network if the application accepts untrusted input for numeric validation. The fix was released in version 10.0.0, which optimizes the regular expression pattern to prevent backtracking.

Affected products

  • Handsontable Handsontable before 10.0.0

Timeline

  • 2021-09-29: disclosed: NVD published
  • 2021-09-30: disclosed: GHSA advisory published
  • 2021-09-30: patched: Fix released in version 10.0.0

References