GHSA-257v-vj4p-3w2h
Regular Expression Denial of Service (ReDOS)
Quick fix
GHSA-257v-vj4p-3w2h — color-string: upgrade to the fixed version with the command below.
npm install color-string@1.5.5Details
In the npm package `color-string`, there is a ReDos (Regular Expression Denial of Service) vulnerability regarding an exponential time complexity for linearly increasing input lengths for `hwb()` color strings.
Strings reaching more than 5000 characters would see several milliseconds of processing time; strings reaching more than 50,000 characters began seeing 1500ms (1.5s) of processing time.
The cause was due to a the regular expression that parses hwb() strings - specifically, the hue value - where the integer portion of the hue value used a 0-or-more quantifier shortly thereafter followed by a 1-or-more quantifier.
This caused excessive backtracking and a cartesian scan, resulting in exponential time complexity given a linear increase in input length.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2021-29060[ADVISORY]
- https://github.com/Qix-/color-string/commit/0789e21284c33d89ebc4ab4ca6f759b9375ac9d3[WEB]
- https://github.com/Qix-/color-string/releases/tag/1.5.5[WEB]
- https://github.com/yetingli/PoCs/blob/main/CVE-2021-29060/Color-String.md[WEB]
- https://github.com/yetingli/SaveResults/blob/main/js/color-string.js[WEB]
- https://www.npmjs.com/package/color-string[WEB]