Executive brief
trim-newlines is a Node.js library that removes leading and trailing newline characters from strings. A regular expression denial-of-service (ReDoS) vulnerability in the .end() method allows an attacker to cause excessive CPU consumption by supplying specially crafted input, potentially disrupting any application that depends on this library.
Technical details
The vulnerability is a regular expression denial-of-service (ReDoS) in the .end() method of the trim-newlines library, classified as CWE-400 (uncontrolled resource consumption). The vulnerable code used a regex pattern that exhibits catastrophic backtracking when processing certain input strings. An attacker can provide a malicious string input that causes the regex engine to consume excessive CPU resources and hang the process. No authentication or special network access is required; the vulnerability is triggered by calling the affected method with malicious input. The vulnerability affects versions before 3.0.1 and 4.0.0 before 4.0.1, and patches are available in the referenced commits.
Affected products
- Sindre Sorhus trim-newlines before 3.0.1 and 4.x before 4.0.1
Timeline
- 2021-05-28: disclosed: NVD published
- 2021-05-27: patched: Fix committed for .end() method
- 2021-06-07: advisory: GHSA-7p7h-4mm5-852v and CVE-2021-33623 published