Executive brief
The color-string library, a popular tool for parsing and generating CSS color strings in JavaScript applications, is vulnerable to a denial-of-service attack. An attacker can provide a specially crafted, long string representing a color (specifically using the HWB format) that causes the application to consume excessive processing time. This can lead to application slowdowns or complete unresponsiveness, impacting service availability.
Technical details
A Regular Expression Denial of Service (ReDoS) vulnerability exists in the `hwb()` color string parser within the `color-string` library. The root cause is a poorly constructed regular expression used to parse the hue value, which contains overlapping quantifiers (a 0-or-more quantifier followed closely by a 1-or-more quantifier). This leads to catastrophic backtracking and exponential time complexity when processing long, invalid input strings. An unauthenticated remote attacker can exploit this by submitting a crafted HWB string (e.g., exceeding 50,000 characters) to any application endpoint that passes user input to the `cs.get()` or `cs.get.hwb()` functions. The vulnerability is fixed in version 1.5.5.
Affected products
- Qix- color-string < 1.5.5
Timeline
- 2021-03-05: patched: Version 1.5.5 released with fix
- 2021-06-21: advisory: NVD and GitHub Advisory published
References
- https://github.com/Qix-/color-string/commit/0789e21284c33d89ebc4ab4ca6f759b9375ac9d3
- https://github.com/Qix-/color-string/releases/tag/1.5.5
- https://github.com/yetingli/PoCs/blob/main/CVE-2021-29060/Color-String.md
- https://github.com/yetingli/SaveResults/blob/main/js/color-string.js
- https://www.npmjs.com/package/color-string