Junglewise Threat Intelligence

CVE-2024-36751: parse-uri Regular expression Denial of Service

CVE-2024-36751 · Severity: medium · CVSS 4 · Published 2025-01-16

Vendors: npm.

Executive brief

parse-uri is a Node.js library that parses and validates URLs. A malicious or malformed URL with repetitive characters can cause the parsing function to hang indefinitely due to catastrophic backtracking in its regular expression pattern, effectively freezing the application and denying service to legitimate users.

Technical details

This is a Regular expression Denial of Service (ReDoS) vulnerability in parse-uri's URL validation regex (CWE-1333, CWE-185). The vulnerable regular expressions on lines 28-29 exhibit catastrophic backtracking when processing crafted URLs containing long sequences of repeating characters followed by patterns that nearly (but don't fully) match the regex. An attacker can supply a malicious URL string (network-reachable, no authentication required) to trigger excessive regex backtracking, consuming CPU and causing the application to hang. Affects parse-uri v1.0.9 and earlier, and parseuri versions before 2.0.0. A patch addressing the regex pattern is available.

Affected products

  • Kikobeats parse-uri 1.0.9 and earlier
  • Kikobeats parseuri before 2.0.0

Timeline

  • 2025-01-16: disclosed: GHSA advisory published
  • 2024-05-22: other: Issue reported on GitHub

References