Junglewise Threat Intelligence

d3-color Regular Expression Denial of Service

Severity: high · Published 2022-09-29

Vendors: npm.

Executive brief

The d3-color library, a popular tool for managing color spaces in web applications, is vulnerable to a flaw that can cause a website to become unresponsive. By providing specifically crafted color strings, an attacker can trigger a Regular Expression Denial of Service (ReDoS), exhausting the server or browser's processing power. This can lead to service outages or a degraded experience for legitimate users.

Technical details

The d3-color library contains an inefficient regular expression (CWE-1333) used for parsing color space representations. An attacker can exploit this by providing a specially crafted input string that triggers catastrophic backtracking, leading to uncontrolled resource consumption (CWE-400) and a Denial of Service (DoS) condition. The vulnerability is reachable via any application interface that passes user-supplied color strings to d3-color functions. The issue is resolved in version 3.1.0 by optimizing the underlying regular expressions.

Affected products

  • d3 d3-color >= 1.0.2, < 3.1.0

Timeline

  • 2022-09-29: advisory: GitHub Advisory GHSA-36jr-mh4h-2g58 published
  • 2022-09-29: patched: Fix released in version 3.1.0

References

Related threats