Executive brief
A vulnerability was found in pm2, a popular process manager for Node.js applications. An attacker can exploit a flaw in how the software handles configuration data to cause a denial-of-service condition. This could lead to high CPU usage and make the application management service unresponsive, potentially impacting the availability of hosted services.
Technical details
A Regular Expression Denial of Service (ReDoS) vulnerability exists in Unitech pm2 prior to version 7.0.0. The flaw is located in the `/lib/tools/Config.js` file, where inefficient regular expression complexity allows for uncontrolled resource consumption. A remote attacker with low privileges can provide specially crafted input that triggers catastrophic backtracking during regex evaluation. This results in excessive CPU consumption, leading to a denial-of-service (DoS) state for the pm2 process. The issue is addressed in version 7.0.0.
Affected products
- Unitech pm2 < 7.0.0
Timeline
- 2025-06-09: disclosed
- 2025-06-09: advisory
- 2025-06-09: patched: Fixed in version 7.0.0