GHSA-257v-vj4p-3w2h

    Dashboard / Vulnerabilities / GHSA-257v-vj4p-3w2h

    GHSA-257v-vj4p-3w2h

    Published: 22 Jun 2021Last Modified: 8 Nov 2023

    Summary: Regular Expression Denial of Service (ReDOS)

    Details: In the npm package `color-string`, there is a ReDos (Regular Expression Denial of Service) vulnerability regarding an exponential time complexity for linearly increasing input lengths for `hwb()` color strings. Strings reaching more than 5000 characters would see several milliseconds of processing time; strings reaching more than 50,000 characters began seeing 1500ms (1.5s) of processing time. The cause was due to a the regular expression that parses hwb() strings - specifically, the hue value - where the integer portion of the hue value used a 0-or-more quantifier shortly thereafter followed by a 1-or-more quantifier. This caused excessive backtracking and a cartesian scan, resulting in exponential time complexity given a linear increase in input length.

    Affected packages

    Package

    Name: color-string

    Purl: pkg:npm/color-string

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -1.5.5

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-257v-vj4p-3w2h | CVE-DB