Junglewise Threat Intelligence

CVE-2023-25166: Sideway formula regular expression denial of service

CVE-2023-25166 · Severity: low · CVSS 3.1 · Published 2023-02-08

Vendors: npm.

Executive brief

@sideway/formula is a JavaScript library used to parse and evaluate formula expressions in applications. A regular expression denial of service (ReDoS) vulnerability allows an attacker to supply specially crafted input strings that cause the parser to consume excessive CPU resources, potentially causing the application to become unresponsive or unavailable.

Technical details

The vulnerability is a Regular Expression Denial of Service (ReDoS) flaw in @sideway/formula's parser, classified as CWE-1333 (Inefficient Regular Expression Complexity). User-provided input strings to the formula parser can trigger polynomial execution time due to inefficient regex patterns with catastrophic backtracking. The attack requires local access and user interaction to supply the malicious formula string. An attacker can exploit this to cause a denial of service by making the application hang or consume excessive CPU. The vulnerability is fixed in version 3.0.1 and later.

Affected products

  • Sideway @sideway/formula < 3.0.1

Timeline

  • 2023-02-08: disclosed
  • 2023-02-08: patched: Version 3.0.1 released

References