Asymmetric denial of service - ReDoS
Description
Within the source code there is evidence of the use of dangerous regular expressions, because they make use of complex operations to find matches, which can lead to an attacker sending a specific string of data that could cause the server to crash when evaluating the string with the dangerous regular expression.
Impact
Generate server crash.
Recommendation
Use optimized regular expressions to perform functions without much computational overhead.
Threat
Anonymous attacker from the Internet.
Expected Remediation Time
⏱️ 60 minutes.
Rules
Kotlin Vulnerable Regex DosJavascript Regex From Untrusted InputTypescript Regex From Untrusted InputJavascript Redos Vulnerable RegexPython User Input In RegexJava Vulnerable Regex With User InputSwift User Input In Regular ExpressionC Sharp Redos Vulnerable RegexGo Redos Vulnerable RegexJava Redos User Input In CompileTypescript Redos Vulnerable RegexPython Regex Dos With Untrusted InputScala Redos With Untrusted InputPhp Regex With User InputC Sharp Untrusted Input In Regex