AdguardTeam / AdguardTeam/FiltersCompiler
Protection from ReDos
- Langage dominant
- JavaScript
- Étoiles
- 64
- Forks
- 11
- Métriques de merge des PR
- Aucune PR mergée en 30 j
Description
Check this issue:
https://github.com/AdguardTeam/AdguardBrowserExtension/issues/2240
The point is that a poor regular expression may cause the extension to completely break the browser.
I suggest adding more checks for regular expressions in the filtering rules.
More on catastrophic backtracking and relevant articles:
* https://javascript.info/regexp-catastrophic-backtracking#back-to-words-and-strings
* https://api7.ai/blog/how-to-avoid-catastrophic-backtracking-completely
* https://github.com/NicolaasWeideman/RegexStaticAnalysis
Instead of static analysis, we may consider checking every regular expression against a few hundreds of random URLs and detect the "slow regexes" this way.
Guide de contribution
Aucun guide de contribution indexé pour ce dépôt
Évaluation
Cette issue n'a pas encore été évaluée.