CyberRota Analysis
AI-GeneratedThe vulnerability affects the anchorme library up to version 3.0.8, which is susceptible to a regular expression denial of service (ReDoS) attack through its IPv6 host extraction regex. By exploiting this flaw, attackers can craft specific input strings that trigger catastrophic backtracking, leading to significant delays in the Node.js event loop and potentially disrupting service for legitimate users. Organizations utilizing this library, particularly those relying on Node.js for web applications, should prioritize patching to mitigate the risk of service disruption.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
anchorme through 3.0.8 contains a regular expression denial of service vulnerability in the IPv6 host extraction regex due to catastrophic backtracking. Attackers can supply specially crafted input strings with repeated patterns to cause exponential regex engine backtracking, blocking the Node.js event loop and denying service to other requests.