AdguardTeam / AdguardTeam/FiltersCompiler

Protection from ReDos

Open
#162 0 comments 1 reaction 0 assignees View on GitHub
enhancement
Dominant language
JavaScript
Stars
64
Forks
11
PR merge metrics
No merged PRs in 30d

Description

Check this issue:
https://github.com/AdguardTeam/AdguardBrowserExtension/issues/2240

The point is that a poor regular expression may cause the extension to completely break the browser.
I suggest adding more checks for regular expressions in the filtering rules.

More on catastrophic backtracking and relevant articles:
* https://javascript.info/regexp-catastrophic-backtracking#back-to-words-and-strings
* https://api7.ai/blog/how-to-avoid-catastrophic-backtracking-completely
* https://github.com/NicolaasWeideman/RegexStaticAnalysis

Instead of static analysis, we may consider checking every regular expression against a few hundreds of random URLs and detect the "slow regexes" this way.

Contributor guide

No contributing guide indexed for this repository

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.