Junglewise Threat Intelligence

CVE-2021-3820: inflect ReDoS via inefficient regex

CVE-2021-3820 · Severity: low · CVSS 3.1 · Published 2021-09-29

Executive brief

inflect is a widely-used Node.js library that provides customizable text inflections (like converting singular to plural forms). The library contains an inefficient regular expression that can be exploited to cause a denial of service by forcing the application to consume excessive CPU resources when processing specially crafted input.

Technical details

The vulnerability is a Regular Expression Denial of Service (ReDoS) issue caused by an inefficient regular expression pattern in the library's core text processing logic (CWE-1333). An attacker can supply specially crafted input to the inflection functions that triggers catastrophic backtracking in the regex engine, consuming CPU and causing the application to hang or become unresponsive. No authentication is required; the attack is network-accessible if the vulnerable library processes untrusted input. The vulnerability was fixed in version 0.3.7.

Affected products

  • inflect inflect before 0.3.7

Timeline

  • 2021-09-29: disclosed
  • 2021-09-28: patched: fix committed

References