Skip to content

semver vulnerable to Regular Expression Denial of Service #7

Description

@luisfuentech

Vulnerability Report

Description:

In security alerts, dependabot is reporting a moderate priority vulnerability.

  • semver vulnerable to Regular Expression Denial of Service
image

Impact:

The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.

Some regular expression engines have a feature called "backtracking". If the token cannot match, the engine "backtracks" to a position that may result in a different token that can match.
Backtracking becomes a weakness if all of these conditions are met:

  • The number of possible backtracking attempts are exponential relative to the length of the input.
  • The input can fail to match the regular expression.
  • The input can be long enough.

Attackers can create crafted inputs that intentionally cause the regular expression to use excessive backtracking in a way that causes the CPU consumption to spike.

Proposed Solution:

Update the library semver from v5.3.0 to v7.5.4 (latest until August 11th/2023). Pull Request

Affected Version:

  • semver < 5.7.2

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions