Executive brief
Mozilla Readability is a library used to extract the main content of a webpage for easier reading, commonly used in browser 'Reader Modes' and content aggregators. A vulnerability was found where processing a specially crafted webpage title can cause the library to consume excessive CPU resources. This can lead to a denial of service, making the application or service using the library unresponsive to users.
Technical details
A Regular Expression Denial of Service (ReDoS) vulnerability exists in @mozilla/readability due to catastrophic backtracking in the regular expression used for title processing. Specifically, the regex `/(.*)[\|\-\\\/ > »] .*/gi` in `Readability.js` can be triggered by long, specially crafted strings (e.g., a long sequence of characters followed by specific delimiters). An attacker can exploit this by providing a malicious document title, causing the Node.js event loop or browser thread to hang due to excessive CPU consumption. The issue was addressed in version 0.6.0 by replacing the inefficient regex with a more performant string manipulation approach using `matchAll` and `substring`.
Affected products
- Mozilla readability < 0.6.0
Timeline
- 2025-03-25: advisory: GitHub Security Advisory published
- 2025-03-26: disclosed: Public disclosure of CVE-2025-2792
- 2025-03-26: patched: Fix released in version 0.6.0