-
-
Notifications
You must be signed in to change notification settings - Fork 1.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
bignumber: parseFixed now contains a ReDoS since a9cdbe1238c149a7167c6bb1a78f314805b52755 #1975
Comments
I was totally unfamiliar with the ReDoS attack; thanks for pointing it out to me and providing concise reproduction steps. :) I’ll research this and get the fix out ASAP! |
The fix is in #1976 which I opened with this issue =). |
Thanks! This will be fixed with #2016, which is removing the regex entirely. Huge thanks for the info on ReDoS though, I need to spend more time understanding the intricacies of it. Reminds me of the quote: "You have problem and think to yourself, 'I know! I can use a regular expression'. Now you have two problems." :) |
This was fixed in 5.4.7. Please let me know if it seems fixed to you (I removed the regex entirely). Thanks for your keen eye! :) |
This is now fixed. |
The new regex introduced in a9cdbe1 contains an IDA, and could cause a ReDoS on some crafted input.
The text was updated successfully, but these errors were encountered: