haystack-ai is vulnerable to Regular Expression Denial-of-service (ReDoS)
60
Medium Risk
Affected versions of this package are vulnerable to Regular Expression Denial-of-service (ReDoS) due to catastrophic backtracking in the QUOTE_SPANS_RE regex pattern, which inefficiently handles malicious inputs containing mismatched or excessive quote characters. An attacker can exploit this vulnerability by crafting a specially designed string with unbalanced quotes, causing the regex engine to perform excessive backtracking, leading to prolonged CPU consumption and potentially denying service to legitimate users.
You are affected if you are using a version that falls within the vulnerable range.
haystack-ai is vulnerable to Regular Expression Denial-of-service (ReDoS) in versions 2.9.0 - 2.13.2.
Upgrade the haystack-ai library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant