Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:40041
HistoryApr 04, 2023 - 2:02 p.m.

Regular Expression Denial Of Service (ReDoS)

2023-04-0414:02:44
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
14
regular expression denial of service
vulnerability
insecure regex pattern
uri
application crash
crafted patterns
security issue

EPSS

0.004

Percentile

72.3%

uri is vulnerable to Regular Expression Denial Of Service (ReDoS). The vulnerability exists due to the insecure Regex pattern used for the RFC3986_URI and RFC3986_relative_ref parameters in the rfc3986_parser.rb, which allows an attacker to crash the application by providing maliciously crafted URI patterns.

References