Executive brief
The es5-ext JavaScript library contains a regular expression vulnerability in its function processing utilities. When functions with very long or complex names are passed to the `function#copy` or `function#toStringTokens` methods, the regex pattern can cause excessive CPU consumption, potentially freezing or stalling the application.
Technical details
The vulnerability is a Regular Expression Denial of Service (ReDoS) flaw residing in the regex patterns used by `function#copy` and `function#toStringTokens` methods in es5-ext versions 0.10.0 through 0.10.62. The vulnerable regex patterns exhibit catastrophic backtracking when processing function definitions with very long names or complex default argument syntax. The attack requires only that the victim application calls these vulnerable functions with attacker-controlled function definitions—no authentication or special privileges are needed. An attacker can exploit this by supplying maliciously crafted functions, causing CPU exhaustion and application stalls. The vulnerability was patched in version 0.10.63 via commits 3551cdd and a52e957, which replaced the problematic regex-based implementation with safer string parsing logic.
Affected products
- medikoo es5-ext 0.10.0 through 0.10.62
Timeline
- 2024-02-26: disclosed: Advisory GHSA-4gmj-3p3h-gm8h published
- 2024-02-26: patched: Fixed in version 0.10.63
References
- https://github.com/medikoo/es5-ext/security/advisories/GHSA-4gmj-3p3h-gm8h
- https://github.com/medikoo/es5-ext/issues/201
- https://github.com/medikoo/es5-ext/commit/3551cdd7b2db08b1632841f819d008757d28e8e2
- https://github.com/medikoo/es5-ext/commit/a52e95736690ad1d465ebcd9791d54570e294602
- https://github.com/medikoo/es5-ext