VDB
Sign up
HIGH7.5

GHSA-mpg4-rc92-vx8v

fast-xml-parser vulnerable to ReDOS at currency parsing

Quick fix

GHSA-mpg4-rc92-vx8v — fast-xml-parser: upgrade to the fixed version with the command below.

npm install fast-xml-parser@4.4.1

Details

### Summary A ReDOS that exists on currency.js was discovered by Gauss Security Labs R&D team.

### Details https://github.com/NaturalIntelligence/fast-xml-parser/blob/v4.4.0/src/v5/valueParsers/currency.js#L10 contains a vulnerable regex

### PoC pass the following string '\t'.repeat(13337) + '.'

### Impact Denial of service during currency parsing in experimental version 5 of fast-xml-parser-library

https://gauss-security.com

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/fast-xml-parser
Introduced in: 4.3.5Fixed in: 4.4.1
Fixnpm install fast-xml-parser@4.4.1

References