Executive brief
@octokit/plugin-paginate-rest is a JavaScript library that handles paginated responses from the GitHub API. A malicious Link header can trigger a regular expression denial of service (ReDoS) attack, causing high CPU usage and making applications unresponsive when processing API responses.
Technical details
This is a regular expression denial of service (ReDoS) vulnerability caused by catastrophic backtracking in the regex pattern /<([^>]+)>;\s*rel="next"/ used to parse Link headers in the iterator.ts file. When the iterator() function processes a specially crafted Link header with repetitive characters (e.g., many angle brackets), the regex engine enters excessive backtracking, consuming CPU cycles and freezing the application. The vulnerability affects all versions from 1.0.0 through 9.2.1, and versions 9.3.0-beta.1 through 11.4.0. No authentication or user interaction is required; an attacker can inject a malicious Link header via network response manipulation. Patches are available in versions 9.2.2 and 11.4.1.
Affected products
- Octokit @octokit/plugin-paginate-rest 1.0.0-9.2.1, 9.3.0-beta.1-11.4.0
Timeline
- 2025-02-14: disclosed: Vulnerability published in GHSA and NVD
- 2025-02-14: patched: Patches released in versions 9.2.2 and 11.4.1