Junglewise Threat Intelligence

CVE-2024-4067: micromatch Regular Expression Denial of Service

CVE-2024-4067 · Severity: low · CVSS 3.1 · Published 2024-05-14

Executive brief

micromatch is a popular JavaScript library used for pattern matching and glob operations in build tools and file processors. A flaw in its braces() function allows attackers to trigger excessive CPU consumption by providing specially crafted input, causing applications to hang or slow down significantly.

Technical details

The vulnerability is a Regular Expression Denial of Service (ReDoS) in the micromatch.braces() function caused by a greedy regex pattern (.*) that will repeatedly backtrack when processing malicious input containing unmatched brackets. No authentication is required; any application calling the affected function with untrusted input is vulnerable. An attacker can supply a carefully crafted payload that forces the regex engine into catastrophic backtracking, consuming CPU resources until the application becomes unresponsive. The issue was partially addressed in a prior fix but persisted, with a complete mitigation requiring a safer regex pattern that avoids greedy matching behavior. Versions prior to 4.0.8 are affected.

Affected products

  • micromatch micromatch <4.0.8

Timeline

  • 2024-05-14: disclosed
  • 2024-05-14: advisory

References

Related threats