Junglewise Threat Intelligence

rgb2hex regular expression denial of service

Severity: low · CVSS 3.1 · Published 2019-08-23

Vendors: npm.

Executive brief

rgb2hex is a JavaScript library that converts RGB and RGBA color values to hexadecimal format. An attacker can cause a denial of service by providing a specially crafted invalid color string that triggers catastrophic backtracking in the library's regular expression parser, consuming excessive CPU and freezing the application.

Technical details

The vulnerability is a Regular Expression Denial of Service (ReDoS) attack in the rgb2hex library. The vulnerable regular expression pattern used to parse RGB/RGBA color strings contains nested quantifiers that cause exponential backtracking when an invalid color value is supplied. An attacker with the ability to pass arbitrary color strings to the rgb2hex function can trigger this condition without requiring authentication or elevated privileges. Successful exploitation results in CPU exhaustion and application unavailability. The fix is available in version 0.1.6 and later.

Affected products

  • Christian Bromann rgb2hex all versions before 0.1.6

Timeline

  • 2019-08-23: disclosed: Published on GitHub advisory database

References

Related threats