Skip to content

Fix missing anchors in validation regex (CWE-777) - #472

Open
navenavelimargam wants to merge 2 commits into
OWASP:masterfrom
navenavelimargam:fix/regex-anchors-241
Open

navenavelimargam wants to merge 2 commits into
OWASP:masterfrom
navenavelimargam:fix/regex-anchors-241

Conversation

@navenavelimargam

Copy link
Copy Markdown

Fixes #241

Added ^ and $ anchors to both regexes in app/routes/profile.js. Without anchors, inputs like evil0198212#evil passed validation.

  • Active ReDoS demo pattern: now /^([0-9]+)+#$/. It is still intentionally vulnerable to backtracking, but it no longer accepts unanchored input.
  • Commented "fix" pattern: now /^[0-9]+#$/.

Verified:
old | valid: true | evil: true
fixed | valid: true | evil: false
vuln+anchors | valid: true | evil: false

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Missing anchors in validation regular expression

1 participant