Junglewise Threat Intelligence

CVE-2021-35065: glob-parent ReDoS in version 6.0.0

CVE-2021-35065 · Severity: low · CVSS 3.1 · Published 2022-07-18

Vendors: npm.

Executive brief

glob-parent is a popular Node.js library that extracts the parent directory path from glob patterns. Version 6.0.0 contains a regular expression that can be exploited to cause excessive CPU consumption (denial of service), potentially freezing or slowing down applications that depend on it when processing malicious input patterns.

Technical details

The vulnerability is a Regular Expression Denial of Service (ReDoS) flaw in glob-parent 6.0.0, classified under CWE-1333 (Inefficient Regular Expression Complexity) and CWE-400 (Uncontrolled Resource Consumption). The regex engine in the library's glob-pattern parsing logic exhibits catastrophic backtracking when given specially crafted input strings, allowing an attacker to cause the regex to consume unbounded CPU time. The attack requires only network access to a service using the affected version and no authentication or user interaction—any call to glob-parent's parsing functions with malicious pattern input can trigger the condition. An attacker can achieve denial of service by causing the application to hang or become unresponsive. The issue is fixed in version 6.0.1 and later.

Affected products

  • glob-parent glob-parent 6.0.0

Timeline

  • 2022-07-18: disclosed
  • 2022-07-18: patched: Fixed in version 6.0.1

References

Related threats