CVE-2021-1333
published 2021-02-04CVE-2021-1333: Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an…
PriorityP351high7.2CVSS 3.1
AVNACLPRHUINSUCHIHAH
EPSS
2.75%
84.7th percentile
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affected device.
Affected
63 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| addressable_project | addressable | >= 2.3.0 < 2.8.0 | 2.8.0 |
| ansi-regex_project | ansi-regex | >= 3.0.0 < 3.0.1 | 3.0.1 |
| ansi-regex_project | ansi-regex | >= 4.0.0 < 4.1.1 | 4.1.1 |
| ansi-regex_project | ansi-regex | >= 5.0.0 < 5.0.1 | 5.0.1 |
| ansi-regex_project | ansi-regex | >= 6.0.0 < 6.0.1 | 6.0.1 |
| axios | axios | >= 0 < 0.21.2 | 0.21.2 |
| browserslist_project | browserslist | >= 4.0.0 < 4.16.5 | 4.16.5 |
| cisco | cisco_small_business_rv_series_router_firmware | — | — |
| cisco | rv016_multi-wan_vpn_router_firmware | <= 4.2.3.14 | — |
| cisco | rv042_dual_wan_vpn_router_firmware | <= 4.2.3.14 | — |
| cisco | rv042g_dual_gigabit_wan_vpn_router_firmware | <= 4.2.3.14 | — |
| cisco | rv082_dual_wan_vpn_router_firmware | <= 4.2.3.14 | — |
| cisco | rv320_dual_gigabit_wan_vpn_router_firmware | <= 1.5.1.11 | — |
| cisco | rv325_dual_gigabit_wan_vpn_router_firmware | <= 1.5.1.11 | — |
| cisco | small_business_rv_series_routers | — | — |
| coder | code-server | >= 0 < 3.12.0 | 3.12.0 |
| cronvel | string-kit | >= 0 < 0.12.8 | 0.12.8 |
| date_project | date | >= 0 < 2.0.1 | 2.0.1 |
| date_project | date | >= 3.0.0 < 3.0.2 | 3.0.2 |
| date_project | date | >= 3.1.0 < 3.1.2 | 3.1.2 |
| date_project | date | >= 3.2.0 < 3.2.1 | 3.2.1 |
| flask-restx_project | flask-restx | >= 0 < 0.5.1 | 0.5.1 |
| github.com | tidwall_gjson | >= 0 < 1.9.3 | 1.9.3 |
| gitlab | gitlab | — | — |
| gitlab | gitlab_ce | — | — |
CVSS provenance
nvdv3.17.2HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
ghsa7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_cisco7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions because of a regular expression denial of service (ReDoS) flaw in the LDAP schem
vendor_msrc·2022-06-14·CVSS 6.5
CVE-2021-46823 [MEDIUM] CWE-1333 python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions because of a regular expression denial of service (ReDoS) flaw in the LDAP schem
python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions because of a regular expression denial of service (ReDoS) flaw in the LDAP schema parser. By sending crafted regex input a remote authenticated attacker could exploit this vulnerability to cause a denial of service condition.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began
Microsoft
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1 3.1.2 3.0.2 and 2.0.1.
vendor_msrc·2022-01-11·CVSS 7.5
CVE-2021-41817 [HIGH] CWE-1333 Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1 3.1.2 3.0.2 and 2.0.1.
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1 3.1.2 3.0.2 and 2.0.1.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Marin
GitLab
CVE-2021-39940: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, a
vendor_gitlab·2021-12-13·CVSS 4.3
CVE-2021-39940 [MEDIUM] CWE-1333 CVE-2021-39940: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, a
CVE-2021-39940: An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab Maven Package registry is vulnerable to a regular expression denial of service when a specifically crafted string is sent.
GitLab
CVE-2021-39933: An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4,
vendor_gitlab·2021-12-13·CVSS 4.3
CVE-2021-39933 [MEDIUM] CWE-1333 CVE-2021-39933: An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4,
CVE-2021-39933: An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression used for handling user input (notes, comments, etc) was susceptible to catastrophic backtracking that could cause a DOS attack.
Red Hat
validator: Inefficient Regular Expression Complexity in Validator.js
vendor_redhat·2021-11-02·CVSS 7.5
CVE-2021-3765 [HIGH] CWE-1333 validator: Inefficient Regular Expression Complexity in Validator.js
validator: Inefficient Regular Expression Complexity in Validator.js
validator.js is vulnerable to Inefficient Regular Expression Complexity
A vulnerability was found in the validator package. Affected versions of this package are vulnerable to Regular expression denial of service (ReDoS) attacks, affecting system availability.
Package: migration-toolkit-virtualization/mtv-ui-rhel8 (Migration Toolkit for Virtualization) - Fix deferred
Package: rhacm2/console-rhel8 (Red Hat Advanced Cluster Management for Kubernetes 2) - Not affected
Package: rhacm2/grc-ui-rhel8 (Red Hat Advanced Cluster Management for Kubernetes 2) - Will not fix
Package: validator (Red Hat Decision Manager 7) - Out of support scope
Package: pcs (Red Hat Enterprise Linux 8) - Not affected
Package: openshift4/ose-co
Red Hat
XStream: ReDoS vulnerability
vendor_redhat·2021-03-12·CVSS 5.3
CVE-2021-21348 [MEDIUM] CWE-1333 XStream: ReDoS vulnerability
XStream: ReDoS vulnerability
XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker to occupy a thread that consumes maximum CPU time and will never return. No user is affected, who followed the recommendation to setup XStream's security framework with a whitelist limited to the minimal required types. If you rely on XStream's default blacklist of the Security Framework, you will have to use at least version 1.4.16.
Statement: OpenShift Container Platform (OCP) delivers Jenkins LTS package with bundled XStream library. Due to JEP-200 [1] and JEP-228 [2] Jenkins projects, OCP Jenkins package is not affected by this flaw.
[1] https://github.com/jenkinsci/jep/blob/master/jep/200/READM
Red Hat
nodejs-is-svg: ReDoS via malicious string
vendor_redhat·2021-03-11·CVSS 7.5
CVE-2021-28092 [HIGH] CWE-1333 nodejs-is-svg: ReDoS via malicious string
nodejs-is-svg: ReDoS via malicious string
The is-svg package 2.1.0 through 4.2.1 for Node.js uses a regular expression that is vulnerable to Regular Expression Denial of Service (ReDoS). If an attacker provides a malicious string, is-svg will get stuck processing the input for a very long time.
A flaw was found in is-svg package. A malicious string provided by an attacker may lead to Regular Expression Denial of Service (ReDoS).
The highest threat from this vulnerability is to availability.
Statement: Red Hat OpenShift Container Platform (RHOCP) 4 delivers the kibana package where the nodejs-is-svg package is bundled, but during the update to container first (to openshift4/ose-logging-kibana6 since OCP 4.5) the dependency was removed and hence kibana package is marked as wontfix. This m
Microsoft
In pygments 1.1+ fixed in 2.7.4 the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and
vendor_msrc·2021-03-09·CVSS 7.5
CVE-2021-27291 [HIGH] CWE-1333 In pygments 1.1+ fixed in 2.7.4 the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and
In pygments 1.1+ fixed in 2.7.4 the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input an attacker can cause a denial of service.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blo
Cisco
Cisco Small Business RV Series Routers Management Interface Remote Command Execution and Denial of Service Vulnerabilities
vendor_cisco·2021-02-03·CVSS 7.2
CVE-2021-1319 [HIGH] CWE-121 Cisco Small Business RV Series Routers Management Interface Remote Command Execution and Denial of Service Vulnerabilities
Cisco Small Business RV Series Routers Management Interface Remote Command Execution and Denial of Service Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly.
These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (Do
Cisco
Cisco Small Business RV Series Routers Management Interface Remote Command Execution and Denial of Service Vulnerabilities
vendor_cisco·CVSS 3.1
CVE-2021-1333 Cisco Small Business RV Series Routers Management Interface Remote Command Execution and Denial of Service Vulnerabilities
CVE-2021-1333: Cisco Small Business RV Series Routers Management Interface Remote Command Execution and Denial of Service Vulnerabilities
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial
GHSA
lambda-middleware Inefficient Regular Expression Complexity vulnerability
ghsa·2024-02-12
CVE-2021-4437 [LOW] CWE-1333 lambda-middleware Inefficient Regular Expression Complexity vulnerability
lambda-middleware Inefficient Regular Expression Complexity vulnerability
A vulnerability, which was classified as problematic, has been found in dbartholomae lambda-middleware frameguard up to 1.0.4. Affected by this issue is some unknown functionality of the file packages/json-deserializer/src/JsonDeserializer.ts of the component JSON Mime-Type Handler. The manipulation leads to inefficient regular expression complexity. Upgrading to version 1.1.0 is able to address this issue. The patch is identified as f689404d830cbc1edd6a1018d3334ff5f44dc6a6. It is recommended to upgrade the affected component. VDB-253406 is the identifier assigned to this vulnerability.
GHSA
mechanize Regular Expression Denial of Service vulnerability
ghsa·2023-01-18
CVE-2021-32837 [HIGH] CWE-1333 mechanize Regular Expression Denial of Service vulnerability
mechanize Regular Expression Denial of Service vulnerability
mechanize, a library for automatically interacting with HTTP web servers, contains a regular expression that is vulnerable to regular expression denial of service (ReDoS) prior to version 0.4.6. If a web server responds in a malicious way, then mechanize could crash. Version 0.4.6 has a patch for the issue.
GHSA
terminal-kit Inefficient Regular Expression Complexity vulnerability
ghsa·2023-01-07
CVE-2021-4306 [HIGH] CWE-1333 terminal-kit Inefficient Regular Expression Complexity vulnerability
terminal-kit Inefficient Regular Expression Complexity vulnerability
A vulnerability classified as problematic has been found in cronvel terminal-kit up to 2.1.7. Affected is an unknown function. The manipulation leads to inefficient regular expression complexity. Upgrading to version 2.1.8 can address this issue. The name of the patch is a2e446cc3927b559d0281683feb9b821e83b758c. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-217620.
GHSA
robots-txt-guard Inefficient Regular Expression Complexity vulnerability
ghsa·2023-01-05
CVE-2021-4305 [HIGH] CWE-1333 robots-txt-guard Inefficient Regular Expression Complexity vulnerability
robots-txt-guard Inefficient Regular Expression Complexity vulnerability
A vulnerability was found in Woorank robots-txt-guard. It has been rated as problematic. Affected by this issue is the function makePathPattern of the file lib/patterns.js. The manipulation of the argument pattern leads to inefficient regular expression complexity. The exploit has been disclosed to the public and may be used. The name of the patch is c03827cd2f9933619c23894ce7c98401ea824020. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-217448.
GHSA
MooTools Regular Expression Denial of Service
ghsa·2023-01-03
CVE-2021-32821 [HIGH] CWE-1333 MooTools Regular Expression Denial of Service
MooTools Regular Expression Denial of Service
MooTools is a collection of JavaScript utilities for JavaScript developers. All known versions include a CSS selector parser that is vulnerable to Regular Expression Denial of Service (ReDoS). An attack requires that an attacker can inject a string into a CSS selector at runtime, which is quite common with e.g. jQuery CSS selectors. No patches are available for this issue.
GHSA
string-kit Inefficient Regular Expression Complexity vulnerability
ghsa·2023-01-02
CVE-2021-4299 [HIGH] CWE-1333 string-kit Inefficient Regular Expression Complexity vulnerability
string-kit Inefficient Regular Expression Complexity vulnerability
A vulnerability classified as problematic was found in cronvel string-kit up to 0.12.7. This vulnerability affects the function naturalSort of the file lib/naturalSort.js. The manipulation leads to inefficient regular expression complexity. The attack can be initiated remotely. Upgrading to version 0.12.8 can address this issue. The name of the patch is 9cac4c298ee92c1695b0695951f1488884a7ca73. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-217180.
GHSA
uri-template-lite Regular Expression Denial of Service
ghsa·2022-08-25
CVE-2021-43309 [MEDIUM] CWE-1333 uri-template-lite Regular Expression Denial of Service
uri-template-lite Regular Expression Denial of Service
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the uri-template-lite npm package, when an attacker is able to supply arbitrary input to the "URI.expand" method.
GHSA
glob-parent 6.0.0 vulnerable to Regular Expression Denial of Service
ghsa·2022-07-18
CVE-2021-35065 [HIGH] CWE-1333 glob-parent 6.0.0 vulnerable to Regular Expression Denial of Service
glob-parent 6.0.0 vulnerable to Regular Expression Denial of Service
glob-parent 6.0.0 is vulnerable to Regular Expression Denial of Service (ReDoS). This issue is fixed in version 6.0.1.
This vulnerability is separate from [GHSA-ww39-953v-wcq6](https://github.com/advisories/GHSA-ww39-953v-wcq6).
GHSA
jquery-validation Regular Expression Denial of Service due to arbitrary input to url2 method
ghsa·2022-07-05·CVSS 7.5
CVE-2022-31147 [MEDIUM] CWE-1333 jquery-validation Regular Expression Denial of Service due to arbitrary input to url2 method
jquery-validation Regular Expression Denial of Service due to arbitrary input to url2 method
Summary
Incomplete fix of CVE-2021-43306: An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the jquery-validation npm package, when an attacker is able to supply arbitrary input to the url2 method.
GHSA
Denial of Service in python-ldap
ghsa·2022-06-19
CVE-2021-46823 [MEDIUM] CWE-1333 Denial of Service in python-ldap
Denial of Service in python-ldap
python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions, because of a regular expression denial of service (ReDoS) flaw in the LDAP schema parser. By sending crafted regex input, a remote authenticated attacker could exploit this vulnerability to cause a denial of service condition.
GHSA
Regular expression denial of service in Delight Nashorn Sandbox
ghsa·2022-06-15
CVE-2021-40660 [HIGH] CWE-1333 Regular expression denial of service in Delight Nashorn Sandbox
Regular expression denial of service in Delight Nashorn Sandbox
An issue was discovered in Delight Nashorn Sandbox. There is an ReDoS vulnerability that can be exploited to launching a denial of service (DoS) attack.
GHSA
Regular expression denial of service in jquery-validation
ghsa·2022-06-03
CVE-2021-43306 [LOW] CWE-1333 Regular expression denial of service in jquery-validation
Regular expression denial of service in jquery-validation
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the jquery-validation npm package, when an attacker is able to supply arbitrary input to the url2 method
GHSA
Regular expression denial of service in semver-regex
ghsa·2022-06-03
CVE-2021-43307 [LOW] CWE-1333 Regular expression denial of service in semver-regex
Regular expression denial of service in semver-regex
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input to the test() method
GHSA
Regular expression denial of service in markdown-link-extractor
ghsa·2022-06-03
CVE-2021-43308 [LOW] CWE-1333 Regular expression denial of service in markdown-link-extractor
Regular expression denial of service in markdown-link-extractor
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the markdown-link-extractor npm package, when an attacker is able to supply arbitrary input to the module's exported function
GHSA
Duplicate Advisory: ReDoS via crafted JSON input in GJSON
ghsa·2022-05-25
CVE-2021-42248 [HIGH] CWE-1333 Duplicate Advisory: ReDoS via crafted JSON input in GJSON
Duplicate Advisory: ReDoS via crafted JSON input in GJSON
## Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-ppj4-34rq-v8j9. This link is maintained to preserve external references.
## Original Description
GJSON <= 1.9.2 allows attackers to cause a redos via crafted JSON input.
GHSA
GHSA-cww6-qwhh-35x7: Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could all
ghsa_unreviewed·2022-05-24
CVE-2021-1333 [HIGH] CWE-121 GHSA-cww6-qwhh-35x7: Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could all
Multiple vulnerabilities in the web-based management interface of Cisco Small Business RV016, RV042, RV042G, RV082, RV320, and RV325 Routers could allow an authenticated, remote attacker to execute arbitrary code or cause an affected device to restart unexpectedly. These vulnerabilities are due to improper validation of user-supplied input in the web-based management interface. An attacker could exploit these vulnerabilities by sending crafted HTTP requests to an affected device. A successful exploit could allow the attacker to execute arbitrary code as the root user on the underlying operating system or cause the device to reload, resulting in a denial of service (DoS) condition. To exploit these vulnerabilities, an attacker would need to have valid administrator credentials on the affect
GHSA
CKEditor 4 ReDoS Vulnerability
ghsa·2022-05-24
CVE-2021-26271 [MEDIUM] CWE-1333 CKEditor 4 ReDoS Vulnerability
CKEditor 4 ReDoS Vulnerability
It was possible to execute a ReDoS-type attack inside CKEditor 4 before 4.16 by persuading a victim to paste crafted text into the Styles input of specific dialogs (in the Advanced Tab for Dialogs plugin).
GHSA
NLTK Vulnerable to REDoS
ghsa·2022-01-06
CVE-2021-3842 [HIGH] CWE-1333 NLTK Vulnerable to REDoS
NLTK Vulnerable to REDoS
NLTK is vulnerable to REDoS in some RegexpTaggers used in the functions `get_pos_tagger` and `malt_regex_tagger`.
GHSA
Regular Expression Denial of Service (ReDoS) in jsx-slack
ghsa·2021-12-17·CVSS 7.5
CVE-2021-43838 [MEDIUM] CWE-1333 Regular Expression Denial of Service (ReDoS) in jsx-slack
Regular Expression Denial of Service (ReDoS) in jsx-slack
jsx-slack v4.5.1 and earlier versions are vulnerable to a regular expression denial-of-service (ReDoS) attack.
### Impact
If attacker can put a lot of JSX elements into `` tag, an internal regular expression for escaping characters may consume an excessive amount of computing resources.
```javascript
/** @jsxImportSource jsx-slack */
import { Section } from 'jsx-slack'
console.log(
{[...Array(40)].map((_, i) => (
{i + 1}
))}
)
```
### Patches
_See also: https://github.com/yhatt/jsx-slack/security/advisories/GHSA-hp68-xhvj-x6j6_
jsx-slack v4.5.2 has updated regular expressions to prevent catastrophic backtracking.
jsx-slack v4.5.1 also had patched a workaround. It has no problems to contents with ASCII characters, but _s
GHSA
ReDos vulnerability on guest checkout email validation
ghsa·2021-12-07
CVE-2021-43805 [HIGH] CWE-1333 ReDos vulnerability on guest checkout email validation
ReDos vulnerability on guest checkout email validation
### Impact
Denial of service vulnerability that could be exploited during a guest checkout. The regular expression used to validate a guest order's email was subject to exponential backtracking through a fragment like `a.a.`.
Before the patch, it can be reproduced in the console like this:
```ruby
irb(main)> Spree::EmailValidator::EMAIL_REGEXP.match "[email protected].@"
processing time: 54.293660s
=> nil
```
To reproduce in the browser, fill in the "Customer Email" field with that fake email address during a guest checkout. Before that, you should open the browser dev tools and change the `type` attribute for that field from `email` to `text`. After entering a fake address and pressing t
GHSA
Regular expression denial of service vulnerability (ReDoS) in date
ghsa·2021-11-16
CVE-2021-41817 [HIGH] CWE-1333 Regular expression denial of service vulnerability (ReDoS) in date
Regular expression denial of service vulnerability (ReDoS) in date
Date’s parsing methods including Date.parse are using Regexps internally, some of which are vulnerable against regular expression denial of service. Applications and libraries that apply such methods to untrusted input may be affected.
The fix limits the input length up to 128 bytes by default instead of changing the regexps. This is because Date gem uses many Regexps and it is possible that there are still undiscovered vulnerable Regexps. For compatibility, it is allowed to remove the limitation by explicitly passing limit keywords as nil like Date.parse(str, limit: nil), but note that it may take a long time to parse.
Please update the date gem to version 3.2.1, 3.1.2, 3.0.2, and 2.0.1, or later. You can use gem update
GHSA
Inefficient Regular Expression Complexity in validator.js
ghsa·2021-11-03
CVE-2021-3765 [MEDIUM] CWE-1333 Inefficient Regular Expression Complexity in validator.js
Inefficient Regular Expression Complexity in validator.js
validator.js prior to 13.7.0 is vulnerable to Inefficient Regular Expression Complexity
GHSA
github.com/tidwall/gjson Vulnerable to REDoS attack
ghsa·2021-10-25
CVE-2021-42836 [HIGH] CWE-1333 github.com/tidwall/gjson Vulnerable to REDoS attack
github.com/tidwall/gjson Vulnerable to REDoS attack
GJSON is a Go package that provides a fast and simple way to get values from a json document. GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.
GHSA
Inefficient Regular Expression Complexity in handsontable
ghsa·2021-09-30
CVE-2021-23446 [HIGH] CWE-1333 Inefficient Regular Expression Complexity in handsontable
Inefficient Regular Expression Complexity in handsontable
The package handsontable from 0 and before 10.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) in `Handsontable.helper.isNumeric` function.
GHSA
NLTK Vulnerable to REDoS
ghsa·2021-09-29
CVE-2021-3828 [HIGH] CWE-1333 NLTK Vulnerable to REDoS
NLTK Vulnerable to REDoS
The nltk package is vulnerable to ReDoS (regular expression denial of service). An attacker that is able to provide as an input to the [`_read_comparison_block()`(https://github.com/nltk/nltk/blob/23f4b1c4b4006b0cb3ec278e801029557cec4e82/nltk/corpus/reader/comparative_sents.py#L259) function in the file `nltk/corpus/reader/comparative_sents.py` may cause an application to consume an excessive amount of CPU.
GHSA
Regular Expression Denial of Service in jsoneditor
ghsa·2021-09-29
CVE-2021-3822 [MEDIUM] CWE-1333 Regular Expression Denial of Service in jsoneditor
Regular Expression Denial of Service in jsoneditor
JSON Editor is a web-based tool to view, edit, format, and validate JSON. It has various modes such as a tree editor, a code editor, and a plain text editor. The jsoneditor package is vulnerable to ReDoS (regular expression denial of service). An attacker that is able to provide a crafted element as input to the getInnerText function may cause an application to consume an excessive amount of CPU. Below pinned line using vulnerable regex.
GHSA
inflect vulnerable to Inefficient Regular Expression Complexity
ghsa·2021-09-29
CVE-2021-3820 [HIGH] CWE-1333 inflect vulnerable to Inefficient Regular Expression Complexity
inflect vulnerable to Inefficient Regular Expression Complexity
inflect is customizable inflections for nodejs. inflect is vulnerable to Inefficient Regular Expression Complexity
GHSA
Inefficient Regular Expression Complexity in taro
ghsa·2021-09-20
CVE-2021-3804 [HIGH] CWE-1333 Inefficient Regular Expression Complexity in taro
Inefficient Regular Expression Complexity in taro
taro is vulnerable to Inefficient Regular Expression Complexity
GHSA
Inefficient Regular Expression Complexity in vuelidate
ghsa·2021-09-20
CVE-2021-3794 [HIGH] CWE-1333 Inefficient Regular Expression Complexity in vuelidate
Inefficient Regular Expression Complexity in vuelidate
vuelidate is a simple, lightweight model-based validation for Vue.js 2.x & 3.0. A ReDoS (regular expression denial of service) flaw was found in the `@vuelidate/validators` package. An attacker that is able to provide crafted input to the url(input) function may cause an application to consume an excessive amount of CPU.
GHSA
Inefficient Regular Expression Complexity in code-server
ghsa·2021-09-20
CVE-2021-3810 [HIGH] CWE-1333 Inefficient Regular Expression Complexity in code-server
Inefficient Regular Expression Complexity in code-server
code-server is vulnerable to Inefficient Regular Expression Complexity
GHSA
Inefficient Regular Expression Complexity in chalk/ansi-regex
ghsa·2021-09-20
CVE-2021-3807 [HIGH] CWE-1333 Inefficient Regular Expression Complexity in chalk/ansi-regex
Inefficient Regular Expression Complexity in chalk/ansi-regex
ansi-regex is vulnerable to Inefficient Regular Expression Complexity which could lead to a denial of service when parsing invalid ANSI escape codes.
**Proof of Concept**
```js
import ansiRegex from 'ansi-regex';
for(var i = 1; i <= 50000; i++) {
var time = Date.now();
var attack_str = "\u001B["+";".repeat(i*10000);
ansiRegex().test(attack_str)
var time_cost = Date.now() - time;
console.log("attack_str.length: " + attack_str.length + ": " + time_cost+" ms")
}
```
The ReDOS is mainly due to the sub-patterns `[[\\]()#;?]*` and `(?:;[-a-zA-Z\\d\\/#&.:=?%@~_]*)*`
GHSA
Inefficient Regular Expression Complexity in nth-check
ghsa·2021-09-20
CVE-2021-3803 [HIGH] CWE-1333 Inefficient Regular Expression Complexity in nth-check
Inefficient Regular Expression Complexity in nth-check
There is a Regular Expression Denial of Service (ReDoS) vulnerability in nth-check that causes a denial of service when parsing crafted invalid CSS nth-checks.
The ReDoS vulnerabilities of the regex are mainly due to the sub-pattern `\s*(?:([+-]?)\s*(\d+))?` with quantified overlapping adjacency and can be exploited with the following code.
**Proof of Concept**
```js
// PoC.js
var nthCheck = require("nth-check")
for(var i = 1; i <= 50000; i++) {
var time = Date.now();
var attack_str = '2n' + ' '.repeat(i*10000)+"!";
try {
nthCheck.parse(attack_str)
}
catch(err) {
var time_cost = Date.now() - time;
console.log("attack_str.length: " + attack_str.length + ": " + time_cost+" ms")
}
}
```
**The Output**
```
attack_str.length: 10003: 174
GHSA
semver-regex Regular Expression Denial of Service (ReDOS)
ghsa·2021-09-20
CVE-2021-3795 [HIGH] CWE-1333 semver-regex Regular Expression Denial of Service (ReDOS)
semver-regex Regular Expression Denial of Service (ReDOS)
npm `semver-regex` is vulnerable to Inefficient Regular Expression Complexity
GHSA
Regular Expression Denial of Service in flask-restx
ghsa·2021-09-08
CVE-2021-32838 [HIGH] CWE-1333 Regular Expression Denial of Service in flask-restx
Regular Expression Denial of Service in flask-restx
Flask RESTX contains a regular expression that is vulnerable to [ReDoS](https://owasp.org/www-community/attacks/Regular_expression_Denial_of_Service_-_ReDoS) (Regular Expression Denial of Service) in `email_regex`.
GHSA
axios Inefficient Regular Expression Complexity vulnerability
ghsa·2021-09-01
CVE-2021-3749 [HIGH] CWE-1333 axios Inefficient Regular Expression Complexity vulnerability
axios Inefficient Regular Expression Complexity vulnerability
axios before v0.21.2 is vulnerable to Inefficient Regular Expression Complexity.
GHSA
Regular Expression Denial of Service in Addressable templates
ghsa·2021-07-12
CVE-2021-32740 [HIGH] CWE-1333 Regular Expression Denial of Service in Addressable templates
Regular Expression Denial of Service in Addressable templates
### Impact
Within the URI template implementation in Addressable, a maliciously crafted template may result in uncontrolled resource consumption, leading to denial of service when matched against a URI. In typical usage, templates would not normally be read from untrusted user input, but nonetheless, no previous security advisory for Addressable has cautioned against doing this. Users of the parsing capabilities in Addressable but not the URI template capabilities are unaffected.
### Patches
The vulnerability was introduced in version 2.3.0 (previously yanked) and has been present in all subsequent versions up to, and including, 2.7.0. It is fixed in version 2.8.0.
### Workarounds
The vulnerability can be avoided by only c
GHSA
markdown2 Regular Expression Denial of Service
ghsa·2021-06-02
CVE-2021-26813 [HIGH] CWE-1333 markdown2 Regular Expression Denial of Service
markdown2 Regular Expression Denial of Service
markdown2 >=1.0.1.18, fixed in 2.4.0, is affected by a regular expression denial of service vulnerability. If an attacker provides a malicious string, it can make markdown2 processing difficult or delayed for an extended period of time.
GHSA
Regular Expression Denial of Service in browserslist
ghsa·2021-05-24
CVE-2021-23364 [MEDIUM] CWE-1333 Regular Expression Denial of Service in browserslist
Regular Expression Denial of Service in browserslist
The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries.
GHSA
Denial of Service in uap-core
ghsa·2021-02-02
CVE-2021-21317 [HIGH] CWE-1333 Denial of Service in uap-core
Denial of Service in uap-core
## Impact
Some regexes are vulnerable to regular expression denial of service (REDoS) due to overlapping capture groups. This allows remote attackers to overload a server by setting the User-Agent header in an HTTP(S) request to maliciously crafted long strings.
## Patches
Please update uap-core to >= v0.11.0
Downstream packages such as uap-python, uap-ruby etc which depend upon uap-core follow different version schemes.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-02-04
Published