Executive brief
micromatch is a popular JavaScript library used for pattern matching and glob operations in build tools and file processors. A flaw in its braces() function allows attackers to trigger excessive CPU consumption by providing specially crafted input, causing applications to hang or slow down significantly.
Technical details
The vulnerability is a Regular Expression Denial of Service (ReDoS) in the micromatch.braces() function caused by a greedy regex pattern (.*) that will repeatedly backtrack when processing malicious input containing unmatched brackets. No authentication is required; any application calling the affected function with untrusted input is vulnerable. An attacker can supply a carefully crafted payload that forces the regex engine into catastrophic backtracking, consuming CPU resources until the application becomes unresponsive. The issue was partially addressed in a prior fix but persisted, with a complete mitigation requiring a safer regex pattern that avoids greedy matching behavior. Versions prior to 4.0.8 are affected.
Affected products
- micromatch micromatch <4.0.8
Timeline
- 2024-05-14: disclosed
- 2024-05-14: advisory