Regular Expression Denial of Service in papaparse
High severity
GitHub Reviewed
Published
Sep 4, 2020
to the GitHub Advisory Database
•
Updated Oct 10, 2023
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Sep 4, 2020
Last updated
Oct 10, 2023
Versions of
papaparse
prior to 5.2.0 are vulnerable to Regular Expression Denial of Service (ReDos). Theparse
function contains a malformed regular expression that takes exponentially longer to process non-numerical inputs. This allows attackers to stall systems and lead to Denial of Service.Recommendation
Upgrade to version 5.2.0 or later.
References