Junglewise Threat Intelligence

express-brute rate limiting bypass

Severity: low · CVSS 3.1 · Published 2019-06-07

Vendors: npm.

Executive brief

express-brute is a Node.js middleware that protects web applications from brute-force attacks by rate-limiting incoming requests. A race condition in the request-counting logic allows attackers to send concurrent requests that are miscounted, enabling them to bypass rate limits entirely and execute more requests than the policy allows. This could allow attackers to brute-force user accounts, passwords, or APIs without hitting the intended throttling delays.

Technical details

The vulnerability is a race condition (CWE-77) in express-brute's request counting mechanism that occurs under high concurrency. When more than approximately 1000 concurrent requests are sent, the package fails to correctly count the total number of requests, allowing attackers to bypass the rate-limiting protection. The attack requires network access to a web application using the vulnerable middleware, with no authentication or user interaction needed. An attacker can exploit this by sending many concurrent requests in parallel, causing the rate limiter to undercount and fail to enforce delays. No patch has been released; the maintainer recommends using an alternative rate-limiting solution.

Affected products

  • express-brute express-brute All versions

Timeline

  • 2019-04-18: disclosed
  • 2019-06-07: advisory

References