Executive brief
A vulnerability in the DotVVM web framework's routing system can allow an attacker to crash or slow down a web application. By sending a specially crafted web request to a site using specific URL patterns, an attacker can trigger a 'Regular Expression Denial of Service' (ReDoS), exhausting server resources and making the site unavailable to legitimate users. This affects applications that use multiple unconstrained parameters in their URL routes.
Technical details
A Regular Expression Denial of Service (ReDoS) vulnerability exists in the DotVVM routing engine (CWE-1333). The flaw is triggered when a route is defined with multiple unconstrained parameters in a single segment (e.g., "{a}-{b}-{c}") without being separated by a slash. An attacker can provide a long string of characters (such as 32,000 dashes) that causes the backtracking regex engine to consume excessive CPU cycles while attempting to match the route. Patches introduce a 1-second timeout for regex operations; upon timeout, the system attempts to switch to a non-backtracking engine or returns an HTTP 503 error. Fixes are available in versions 4.2.11, 4.3.15, and 5.0.0-preview09.
Affected products
- riganti DotVVM < 4.2.11, > 4.3.0-preview01-final, < 4.3.15, >= 5.0.0-preview01-final, < 5.0.0-preview09-final
Timeline
- 2026-06-18: disclosed
- 2026-06-19: advisory