Executive brief
http-cache-semantics is a JavaScript library that implements HTTP caching rules used by web servers and applications to manage cached content. An attacker can send specially crafted HTTP headers that trigger an inefficient regular expression in the library, causing the server to consume excessive CPU and become unresponsive, resulting in a denial of service.
Technical details
The vulnerability is a Regular Expression Denial of Service (ReDoS) flaw in http-cache-semantics versions before 4.1.1, caused by inefficient regex pattern complexity (CWE-1333) used for whitespace trimming in header parsing. The vulnerable code resides in the parseCacheControl function that processes HTTP Cache-Control and similar headers. An attacker can exploit this by sending malicious header values with repeated patterns that cause catastrophic backtracking in the regex engine, requiring no authentication or special preconditions. The attack vector is network-based: requests are sent to a server that uses this library to read cache policies from incoming requests. The patch (commit 560b2d8) replaces the regex-based whitespace trimming with a more efficient string manipulation approach, fixing the issue in version 4.1.1 and later.
Affected products
- npm http-cache-semantics before 4.1.1
Timeline
- 2023-01-31: disclosed
- 2023-01-31: patched: Fixed in version 4.1.1