Junglewise Threat Intelligence

CVE-2025-58451: Cattown inefficient regular expression complexity

CVE-2025-58451 · Severity: medium · CVSS 4 · Published 2025-09-09

Vendors: npm.

Executive brief

Cattown is a Node.js package that uses regular expressions for input processing. The package contains inefficient regex patterns with exponential worst-case complexity that can be exploited by sending specially crafted inputs, causing excessive CPU consumption and service outages.

Technical details

Cattown versions prior to 1.0.2 contain inefficient regular expressions (CWE-1333) with exponential worst-case complexity and uncontrolled resource consumption vulnerabilities (CWE-400). Malicious inputs can trigger excessive regex backtracking, causing high CPU usage and memory exhaustion, potentially leading to denial of service. The vulnerability is network-reachable if the package is exposed to untrusted input, and requires no authentication or user interaction. The issue was identified through static analysis and has been fixed in version 1.0.2.

Affected products

  • IEatUranium238 Cattown < 1.0.2

Timeline

  • 2025-09-09: disclosed
  • 2025-09-09: patched: Fixed in version 1.0.2

References