ash is vulnerable to Regular Expression Denial of Service (ReDoS)
59
Medium Risk
The Ash.Type.String constraint checker runs a configured match regular expression against the full input even after the value has failed its length constraint. Constraints are combined without early termination, so an oversized untrusted input with a backtracking prone pattern still runs that expensive match, leading to high CPU use and denial of service. The fix skips the match regex once a length constraint is violated.
You are affected if you are using a version that falls within the vulnerable range and you use string attributes with both a length constraint and a match regular expression on externally supplied input.
ash is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 0.10.0 - 3.32.1.
Upgrade the ash library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.