Junglewise Threat Intelligence

CVE-2024-25355: s3-url-parser ReDoS vulnerability in regex parsing

CVE-2024-25355 · Severity: low · CVSS 3.1 · Published 2024-05-01

Vendors: npm.

Executive brief

s3-url-parser is a JavaScript library used to extract bucket names, regions, and keys from Amazon S3 URLs. The library contains regular expressions vulnerable to catastrophic backtracking; an attacker can send a specially crafted URL with repeated characters that causes the parser to hang or crash, disrupting any application that depends on it.

Technical details

The vulnerability is a Regular Expression Denial of Service (ReDoS) in three regex patterns defined in the main parsing module (lines 7, 17, and 27 of index.js). The vulnerable regexes lack proper anchors and quantifier constraints, allowing catastrophic backtracking when processing input containing long sequences of repeated characters (e.g., many colons). An attacker can trigger a denial of service by providing a malformed URL with a long repetitive payload (reproducible with 199,999+ colons), causing the application to hang or crash. The vulnerability requires network access to an application using s3-url-parser but no authentication or user interaction. A patch addressing the regex patterns is available.

Affected products

  • npm s3-url-parser 1.0.3

Timeline

  • 2024-04-29: disclosed
  • 2024-05-01: advisory

References