Launch Week Day 1: Announcing Security Design Review
HIGH 7.5 RubyGems

Inefficient Regular Expression Complexity in Loofah

GHSA-486f-hjj9-9vhh · CVE-2022-23514

Published · Modified

Description

Summary

Loofah < 2.19.1 contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service through CPU resource consumption.

Mitigation

Upgrade to Loofah >= 2.19.1.

Severity

The Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1).

References

Credit

This vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q).

Ready to move

Start Securing

Free, no credit card | First findings in minutes