Executive brief
underscore.string is a JavaScript utility library providing string manipulation functions. A regular expression denial of service (ReDoS) vulnerability in the unescapeHTML function allows an attacker to supply specially crafted input that causes the application to hang or become unresponsive, potentially leading to service outages or resource exhaustion.
Technical details
The vulnerability is a Regular Expression Denial of Service (ReDoS) in the unescapeHTML function caused by an overly-broad regular expression pattern. An attacker can craft a malicious string input that triggers catastrophic backtracking in the regex engine, causing exponential slowdown. The advisory notes approximately 2 seconds of slowdown for 50,000 characters, growing exponentially with larger inputs. This is a network-reachable vulnerability if the affected function processes untrusted user input. The vulnerability was fixed in version 3.3.5 and later.
Affected products
- underscore.string underscore.string before 3.3.5
Timeline
- 2019-06-14: disclosed: Published in GitHub Advisory Database