Junglewise Threat Intelligence

CVE-2022-29167: Mozilla Hawk regular expression denial of service

CVE-2022-29167 · Severity: low · CVSS 3.1 · Published 2022-05-23

Vendors: npm, Mozilla.

Executive brief

Hawk is an HTTP authentication library used to cryptographically verify authenticated requests. The library contained a vulnerable regular expression in its Host header parsing function that could be exploited by sending specially crafted input, causing the server to consume CPU exponentially and become unresponsive. An attacker can trigger this denial of service condition remotely without authentication.

Technical details

The vulnerability is a regular expression denial of service (ReDoS) in the Hawk.utils.parseHost() function, which uses a vulnerable regex pattern to parse the Host HTTP header. The vulnerable regex exhibits exponential backtracking behavior when processing adversarial input—each additional character in the attacker's crafted Host header causes computation time to increase exponentially, enabling a remote denial of service attack. The attack requires no authentication and is triggered by any HTTP request with a malicious Host header value. The vulnerability was patched in version 9.0.1 by replacing the vulnerable regex with the built-in URL class for parsing. Workarounds exist: callers of Hawk.authenticate() can pre-parse and supply the host and port in the options argument to bypass the vulnerable parseHost() function.

Affected products

  • Mozilla Hawk <9.0.1

Timeline

  • 2022-05-04: disclosed
  • 2022-05-03: patched: Fix merged in PR #286

References