Executive brief
MathJax is a JavaScript library that displays mathematical notation in web browsers. The library contains two regular expressions with algorithmic complexity vulnerabilities that can be exploited to cause denial of service. An attacker who can control input passed to certain MathJax functions could craft malicious strings that cause the library to consume excessive CPU resources, making the application unresponsive.
Technical details
MathJax v2.7.9 and earlier contains two Regular Expression Denial of Service (ReDoS) vulnerabilities in the "pattern" and "markdownPattern" regular expressions within MathJax.js. The vulnerable patterns exhibit exponential backtracking behavior when processing specially crafted input strings. The vulnerability can be triggered via MathJax.Message.Set() or MathJax.Localization._() functions if an attacker can control the input; however, the vendor disputes the practical risk, noting that these regular expressions are not applied to untrusted user input in typical deployments. Exploitation would result in CPU exhaustion and application denial of service.
Affected products
- MathJax MathJax up to 2.7.9
Timeline
- 2023-07-29: disclosed
- 2023-08-29: advisory