Executive brief
A denial-of-service vulnerability exists in js-video-url-parser, a library used to extract information like video IDs and timestamps from URLs. By providing a specially crafted video URL with a malicious timestamp parameter, an attacker can cause the application to freeze or become unresponsive. This can lead to a disruption of service for users of applications that rely on this library to process video links.
Technical details
A Regular Expression Denial of Service (ReDoS) vulnerability exists in js-video-url-parser versions 0.1.3 through 0.5.1. The getTime() function in lib/util.js uses an inefficient regular expression (/^(\d+[smhdw]?)+$/) to validate timestamp parameters. Due to nested quantifiers, a crafted string with a long sequence of digits followed by an invalid character triggers catastrophic backtracking. An unauthenticated remote attacker can exploit this by supplying a malicious 't' or 'start' parameter to any application calling urlParser.parse(), causing the Node.js event loop to block and resulting in a denial of service. As of the advisory date, no patch is available and the repository has been archived.
Affected products
- Zod js-video-url-parser 0.1.3 to 0.5.1
Timeline
- 2026-03-28: disclosed: Issue reported on GitHub repository
- 2026-04-09: advisory: NVD publication date
- 2026-04-10: advisory: GitHub Advisory published
- 2026-04-24: other: GitHub repository archived by owner