{"id":"CVE-2026-57577","aliases":["GHSA-c2g3-c4gc-w5wg"],"url":"https://o3.security/vulnerability/CVE-2026-57577","summary":"DotVVM: ReDOS in routing","details":"DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, a route containing multiple unconstrained parameters in one path segment can cause excessive regular-expression backtracking in DotvvmRoute.IsMatch when a remote requester supplies a long near-match path. DotvvmRouteParser.RouteRegex previously had no matching timeout. Patched runtimes retry with the .NET non-backtracking engine, while runtimes that do not support non-backtracking matching return HTTP 503 after the one-second timeout in DotvvmRoutingMiddleware. This issue is fixed in versions 4.2.11, 4.3.15, and 5.0.0-preview09-final.","published":"2026-09-14T17:37:54.739Z","modified":"2026-09-16T03:46:53.588648888Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/riganti/dotvvm/commit/1635245b5eaf9ccf8e3536b9d8b1941819526585","label":"riganti/dotvvm@1635245"},"references":[{"type":"WEB","url":"https://github.com/riganti/dotvvm/releases/tag/v4.3.15"},{"type":"WEB","url":"https://github.com/riganti/dotvvm/releases/tag/v5.0.0-preview09"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57577.json"},{"type":"ADVISORY","url":"https://github.com/riganti/dotvvm/security/advisories/GHSA-c2g3-c4gc-w5wg"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57577"},{"type":"FIX","url":"https://github.com/riganti/dotvvm/commit/1635245b5eaf9ccf8e3536b9d8b1941819526585"},{"type":"FIX","url":"https://github.com/riganti/dotvvm/commit/4fc26a8591c76fb92ed701352c2a84120cf926c5"},{"type":"FIX","url":"https://github.com/riganti/dotvvm/commit/5728ab80fff9af883b44d11c118d2e8a8991dcd4"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-09-16T03:46:53.588648888Z"}}