{"id":"GHSA-x4hg-hfwf-p9mw","aliases":[],"url":"https://o3.security/vulnerability/GHSA-x4hg-hfwf-p9mw","summary":"@asymmetric-effort/nogginlessdom vulnerable to ReDoS via user-controlled regex in HTMLInputElement pattern validation","details":"## Summary\n\nThe `HTMLInputElement.checkValidity()` method constructed a `RegExp` directly from the user-controlled `pattern` property without any sanitization or timeout protection. This allowed an attacker to inject a regex with catastrophic backtracking, freezing the event loop.\n\n## Fix\n\nFixed in commit https://github.com/asymmetric-effort/NogginLessDom/commit/25a3cbac665fae5663f8b71c073b80c3152dbe7b on `main`. Added:\n- Pattern length limit (1024 characters)\n- Nested quantifier detection (`hasNestedQuantifiers`) that rejects patterns like `(a+)+` before constructing the regex\n- Patterns exceeding limits are treated as non-matching (safe default)","published":"2026-07-02T20:20:04Z","modified":"2026-07-02T20:30:11.377423261Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"@asymmetric-effort/nogginlessdom","fixedVersion":"0.0.22"}],"fix":{"url":"https://github.com/asymmetric-effort/NogginLessDom/commit/25a3cbac665fae5663f8b71c073b80c3152dbe7b","label":"asymmetric-effort/NogginLessDom@25a3cba"},"references":[{"type":"WEB","url":"https://github.com/asymmetric-effort/NogginLessDom/security/advisories/GHSA-x4hg-hfwf-p9mw"},{"type":"WEB","url":"https://github.com/asymmetric-effort/NogginLessDom/commit/25a3cbac665fae5663f8b71c073b80c3152dbe7b"},{"type":"PACKAGE","url":"https://github.com/asymmetric-effort/NogginLessDom"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-02T20:30:11.377423261Z"}}