VDB
Sign up
HIGH7.5

GHSA-3xq5-wjfh-ppjc

Luxon Inefficient Regular Expression Complexity vulnerability

Quick fix

GHSA-3xq5-wjfh-ppjc — luxon: upgrade to the fixed version with the command below.

npm install luxon@1.28.1

Details

# Impact Luxon's `DateTime.fromRFC2822() has quadratic (N^2) complexity on some specific inputs. This causes a noticeable slowdown for inputs with lengths above 10k characters. Users providing untrusted data to this method are therefore vulnerable to (Re)DoS attacks.

This is the same bug as Moment's https://github.com/moment/moment/security/advisories/GHSA-wc69-rhjr-hc9g

# Workarounds Limit the length of the input.

# References There is an excellent writeup of the same issue in Moment: https://github.com/moment/moment/pull/6015#issuecomment-1152961973

# Details `DateTime.fromRFC2822("(".repeat(500000))` takes a couple minutes to complete.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/luxon
Introduced in: 1.0.0Fixed in: 1.28.1
Fixnpm install luxon@1.28.1
npm/luxon
Introduced in: 2.0.0Fixed in: 2.5.2
Fixnpm install luxon@2.5.2
npm/luxon
Introduced in: 3.0.0Fixed in: 3.2.1
Fixnpm install luxon@3.2.1

References