CVE-2024-41818
published 2024-07-29CVE-2024-41818: fast-xml-parser is an open source, pure javascript xml parser. a ReDOS exists on currency.js. This vulnerability is fixed in 4.4.1.
PriorityP337high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.83%
53.7th percentile
fast-xml-parser is an open source, pure javascript xml parser. a ReDOS exists on currency.js. This vulnerability is fixed in 4.4.1.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | node-webfont | — | — |
| naturalintelligence | fast-xml-parser | — | — |
| naturalintelligence | fast-xml-parser | — | — |
| naturalintelligence | fast-xml-parser | >= 4.3.5 < 4.4.1 | 4.4.1 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
vendor_debian7.5LOW
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
fast-xml-parser: ReDOS at currency parsing in currency.js
vendor_redhat·2024-07-28·CVSS 7.5
CVE-2024-41818 [HIGH] CWE-400 fast-xml-parser: ReDOS at currency parsing in currency.js
fast-xml-parser: ReDOS at currency parsing in currency.js
fast-xml-parser is an open source, pure javascript xml parser. a ReDOS exists on currency.js. This vulnerability is fixed in 4.4.1.
A regular expression denial of service (ReDoS) flaw was found in fast-xml-parser in the currency.js script. By sending a specially crafted regex input, a remote attacker could cause a denial of service condition.
Statement: Red Hat has decided to rate this vulnerability as Important due to the potential loss of Availability and the low complexity.
Package: mta/mta-ui-rhel8 (Migration Toolkit for Applications 6) - Will not fix
Package: mta/mta-ui-rhel9 (Migration Toolkit for Applications 7) - Not affected
Package: fast-xml-parser (OpenShift Serverless) - Will not fix
Package: rhdh-operator-contain
Debian
CVE-2024-41818: node-webfont - fast-xml-parser is an open source, pure javascript xml parser. a ReDOS exists on...
vendor_debian·2024·CVSS 7.5
CVE-2024-41818 [HIGH] CVE-2024-41818: node-webfont - fast-xml-parser is an open source, pure javascript xml parser. a ReDOS exists on...
fast-xml-parser is an open source, pure javascript xml parser. a ReDOS exists on currency.js. This vulnerability is fixed in 4.4.1.
Scope: local
bookworm: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
fast-xml-parser vulnerable to ReDOS at currency parsing
ghsa·2024-07-29
CVE-2024-41818 [HIGH] CWE-1333 fast-xml-parser vulnerable to ReDOS at currency parsing
fast-xml-parser vulnerable to ReDOS at currency parsing
### Summary
A ReDOS that exists on currency.js was discovered by Gauss Security Labs R&D team.
### Details
https://github.com/NaturalIntelligence/fast-xml-parser/blob/v4.4.0/src/v5/valueParsers/currency.js#L10 contains a vulnerable regex
### PoC
pass the following string '\t'.repeat(13337) + '.'
### Impact
Denial of service during currency parsing in experimental version 5 of fast-xml-parser-library
https://gauss-security.com
OSV
fast-xml-parser vulnerable to ReDOS at currency parsing
osv·2024-07-29
CVE-2024-41818 [HIGH] fast-xml-parser vulnerable to ReDOS at currency parsing
fast-xml-parser vulnerable to ReDOS at currency parsing
### Summary
A ReDOS that exists on currency.js was discovered by Gauss Security Labs R&D team.
### Details
https://github.com/NaturalIntelligence/fast-xml-parser/blob/v4.4.0/src/v5/valueParsers/currency.js#L10 contains a vulnerable regex
### PoC
pass the following string '\t'.repeat(13337) + '.'
### Impact
Denial of service during currency parsing in experimental version 5 of fast-xml-parser-library
https://gauss-security.com
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/NaturalIntelligence/fast-xml-parser/blob/master/src/v5/valueParsers/currency.js#L10https://github.com/NaturalIntelligence/fast-xml-parser/commit/ba5f35e7680468acd7906eaabb2f69e28ed8b2aahttps://github.com/NaturalIntelligence/fast-xml-parser/commit/d0bfe8a3a2813a185f39591bbef222212d856164https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-mpg4-rc92-vx8vhttps://github.com/NaturalIntelligence/fast-xml-parser/blob/master/src/v5/valueParsers/currency.js#L10https://github.com/NaturalIntelligence/fast-xml-parser/commit/d0bfe8a3a2813a185f39591bbef222212d856164https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-mpg4-rc92-vx8v
2024-07-29
Published