Junglewise Threat Intelligence

CVE-2021-29060: Qix- color-string ReDoS in hwb parser

CVE-2021-29060 · Severity: low · CVSS 3.1 · Published 2021-06-22

Vendors: npm.

Executive brief

The color-string library, a popular tool for parsing and generating CSS color strings in JavaScript applications, is vulnerable to a denial-of-service attack. An attacker can provide a specially crafted, long string representing a color (specifically using the HWB format) that causes the application to consume excessive processing time. This can lead to application slowdowns or complete unresponsiveness, impacting service availability.

Technical details

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the `hwb()` color string parser within the `color-string` library. The root cause is a poorly constructed regular expression used to parse the hue value, which contains overlapping quantifiers (a 0-or-more quantifier followed closely by a 1-or-more quantifier). This leads to catastrophic backtracking and exponential time complexity when processing long, invalid input strings. An unauthenticated remote attacker can exploit this by submitting a crafted HWB string (e.g., exceeding 50,000 characters) to any application endpoint that passes user input to the `cs.get()` or `cs.get.hwb()` functions. The vulnerability is fixed in version 1.5.5.

Affected products

  • Qix- color-string < 1.5.5

Timeline

  • 2021-03-05: patched: Version 1.5.5 released with fix
  • 2021-06-21: advisory: NVD and GitHub Advisory published

References

Related threats