Executive brief
sanitize-html is a popular JavaScript library used to remove malicious code from HTML content on websites and web applications. A regular expression bug in the HTML comment removal logic allows attackers to send specially crafted input that causes the library to consume excessive CPU resources, potentially slowing or crashing the affected application and denying service to legitimate users.
Technical details
The vulnerability is a Regular Expression Denial of Service (ReDoS) flaw in the global regular expression replacement logic used for HTML comment removal in sanitize-html versions before 2.7.1. The vulnerable code uses a poorly constructed regex pattern that exhibits catastrophic backtracking when processing certain malformed input. An attacker can craft HTML containing nested or specially formatted comments to trigger the ReDoS condition, causing the regex engine to enter exponential time complexity. No authentication or special privileges are required; the vulnerability is triggered when untrusted HTML input is processed by the library. The fix was released in version 2.7.1 with an improved regex pattern that avoids pathological backtracking.
Affected products
- Apostrophe CMS sanitize-html before 2.7.1
Timeline
- 2022-08-31: disclosed
- 2022-07-20: patched: Version 2.7.1 released with fix