Junglewise Threat Intelligence

CVE-2023-22467: Luxon ReDoS in DateTime.fromRFC2822

CVE-2023-22467 · Severity: low · CVSS 3.1 · Published 2023-01-09

Executive brief

Luxon, a popular JavaScript library for date and time manipulation, contains a performance flaw in how it processes certain date formats. An attacker can send a specially crafted, long string to an application using this library, causing the system to consume excessive CPU resources and become unresponsive. This effectively results in a denial-of-service (DoS) attack, potentially crashing the application or making it unavailable to legitimate users.

Technical details

A Regular Expression Denial of Service (ReDoS) vulnerability exists in Luxon's `DateTime.fromRFC2822()` method. The root cause is an inefficient regular expression used in the `preprocessRFC2822` function to strip comments and whitespace, which exhibits quadratic (N^2) time complexity when processing specific malformed inputs (such as a long string of opening parentheses). An unauthenticated remote attacker can exploit this by providing a crafted string exceeding 10,000 characters, leading to CPU exhaustion and service instability. The issue has been patched by updating the regex to prevent excessive backtracking.

Affected products

  • moment luxon 1.x <= 1.28.0, 2.x <= 2.5.1, 3.x <= 3.2.0

Timeline

  • 2023-01-04: advisory: Initial disclosure and NVD publication
  • 2023-01-09: disclosed: GitHub Security Advisory published

References