Junglewise Threat Intelligence

CVE-2021-33502: normalize-url ReDoS vulnerability in data URL handling

CVE-2021-33502 · Severity: low · CVSS 3.1 · Published 2021-06-08

Executive brief

normalize-url is a popular Node.js library used to standardize and clean up URL strings. A regular expression flaw in the library allows attackers to send specially crafted data: URLs that cause exponential processing delays, effectively freezing or crashing any application that uses the library to process untrusted URLs. This can lead to denial of service attacks against web services.

Technical details

The vulnerability is a Regular Expression Denial of Service (ReDoS) vulnerability in the normalize-url library, specifically in the handling of data: URLs. The vulnerable regex pattern exhibits catastrophic backtracking when processing malformed or long data: URLs, allowing an attacker to cause exponential CPU consumption. The attack vector is network-accessible if the application processes user-supplied URLs. No authentication is required. An attacker can trigger the vulnerability by sending a specially crafted data: URL, causing the application to hang or become unresponsive. The fix was released in versions 4.5.1, 5.3.1, and 6.0.1, which optimize the regex pattern to prevent backtracking.

Affected products

  • sindresorhus normalize-url 4.3.0 to 4.5.0, 5.0.0 to 5.3.0, 6.0.0

Timeline

  • 2021-05-24: disclosed: NVD publication date
  • 2021-05-28: patched: GitHub advisory reviewed; patches released in versions 4.5.1, 5.3.1, and 6.0.1

References