Executive brief
A performance flaw was found in tiny-regex-c, a small library used for processing regular expressions in C-based applications. An attacker can provide a specially crafted search pattern that causes the library to consume excessive processor time, potentially leading to a system slowdown or a denial-of-service. This impact is limited to the local system where the software is running.
Technical details
A Regular Expression Denial of Service (ReDoS) vulnerability exists in the matchstar and matchplus functions within re.c of kokke tiny-regex-c. The root cause is inefficient backtracking logic when handling greedy quantifiers (* and +). When multiple greedy quantifiers are chained (e.g., "a*a*a*b") and a match fails near the end of the input, the engine repeatedly redistributes the input across each quantifier, leading to exponential time complexity. An attacker with local access can exploit this by providing a malicious pattern or input, resulting in uncontrolled resource consumption (CPU). As of the advisory date, the project has not yet released a patch.
Affected products
- kokke tiny-regex-c up to f2632c6d9ed25272987471cdb8b70395c2460bdb
Timeline
- 2026-05-20: disclosed: Issue reported to the maintainer on GitHub
- 2026-06-08: advisory: CVE published by VulDB/NVD