Junglewise Threat Intelligence

CVE-2022-31110: RSSHub denial of service in filter parameters

CVE-2022-31110 · Severity: low · CVSS 3.1 · Published 2022-06-23

Technologies: rsshub (npm). Vendors: npm.

Executive brief

RSSHub is a feed aggregation service that converts various web content sources into RSS feeds. A denial of service vulnerability allows attackers to craft malicious requests with special values in filter parameters, causing abnormally high CPU usage that degrades service performance for all users.

Technical details

This vulnerability is a resource exhaustion / denial of service in RSSHub's filter and filterout request parameters. An attacker can pass specially crafted values to these parameters without authentication, triggering inefficient processing logic that consumes excessive CPU resources. The attack requires network access and no special privileges or user interaction. Impact is availability degradation; no data compromise or code execution is possible. The vulnerability was patched in commit 5c4177441417b44a6e45c3c63e9eac2504abeb5b and users should upgrade immediately.

Affected products

  • RSSHub RSSHub through 1.0.0

Timeline

  • 2022-06-22: disclosed
  • 2022-06-23: patched

References

Related threats