Executive brief
Highcharts is a popular JavaScript charting library used to display data visualizations in web applications. A regular expression processing flaw in the SVG text rendering component could be exploited by an attacker to craft malicious input that causes excessive CPU consumption, potentially making the charting functionality unresponsive and affecting the entire web application's performance.
Technical details
The vulnerability is a Regular Expression Denial of Service (ReDoS) flaw in the SVGRenderer text attribute processing code. The vulnerability existed in backtracking regular expressions used to parse and replace class, href, and style attributes in SVG text strings. An attacker could provide specially crafted input containing repeated patterns that cause exponential backtracking in the regex engine, leading to denial of service. The fix, implemented in commit 7c547e1, refactored the SVG text rendering to eliminate the problematic backtracking regexes. The vulnerability was patched in version 6.1.0.
Affected products
- Highcharts Highcharts before 6.1.0
Timeline
- 2020-08-19: disclosed