Executive brief
Luxon, a popular JavaScript library for date and time manipulation, contains a performance flaw in how it processes certain date formats. An attacker can send a specially crafted, long string to an application using this library, causing the system to consume excessive CPU resources and become unresponsive. This effectively results in a denial-of-service (DoS) attack, potentially crashing the application or making it unavailable to legitimate users.
Technical details
A Regular Expression Denial of Service (ReDoS) vulnerability exists in Luxon's `DateTime.fromRFC2822()` method. The root cause is an inefficient regular expression used in the `preprocessRFC2822` function to strip comments and whitespace, which exhibits quadratic (N^2) time complexity when processing specific malformed inputs (such as a long string of opening parentheses). An unauthenticated remote attacker can exploit this by providing a crafted string exceeding 10,000 characters, leading to CPU exhaustion and service instability. The issue has been patched by updating the regex to prevent excessive backtracking.
Affected products
- moment luxon 1.x <= 1.28.0, 2.x <= 2.5.1, 3.x <= 3.2.0
Timeline
- 2023-01-04: advisory: Initial disclosure and NVD publication
- 2023-01-09: disclosed: GitHub Security Advisory published
References
- https://github.com/moment/luxon/security/advisories/GHSA-3xq5-wjfh-ppjc
- https://github.com/moment/moment/security/advisories/GHSA-wc69-rhjr-hc9g
- https://github.com/moment/moment/pull/6015
- https://github.com/moment/luxon/commit/5ab3bf64a10da929a437629cdb2f059bb83212bf
- https://github.com/moment/luxon
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/44I3WAJKYXDLOVYRGMHAUXMIV4SPFXDZ