Executive brief
Meteor is a popular full-stack JavaScript framework used to build web applications. A vulnerability in its DDP (Distributed Data Protocol) server component allows remote attackers to trigger excessive CPU consumption through a maliciously crafted request, potentially causing service degradation or denial of service for application users.
Technical details
This vulnerability is a ReDoS (Regular Expression Denial of Service) issue classified as CWE-400 affecting the Object.assign function in packages/ddp-server/livedata_server.js. The forwardedFor argument is processed using an inefficient regular expression that exhibits catastrophic backtracking when given specially crafted input. The attack requires network accessibility to the Meteor application but has high complexity and is difficult to exploit in practice. Exploitation leads to denial of service through resource exhaustion. The vulnerability was patched in version 3.2.2 (commit f7ea6817b90952baaea9baace2a3b4366fee6a63).
Affected products
- Meteor Meteor up to 3.2.1
Timeline
- 2025-05-16: disclosed
- 2025-05-16: patched: Version 3.2.2 released with fix