AdguardTeam / AdguardTeam/FiltersCompiler
Protection from ReDos
- Dominant language
- JavaScript
- Stars
- 64
- Forks
- 11
- PR merge metrics
- No merged PRs in 30d
Description
Check this issue:
https://github.com/AdguardTeam/AdguardBrowserExtension/issues/2240
The point is that a poor regular expression may cause the extension to completely break the browser.
I suggest adding more checks for regular expressions in the filtering rules.
More on catastrophic backtracking and relevant articles:
* https://javascript.info/regexp-catastrophic-backtracking#back-to-words-and-strings
* https://api7.ai/blog/how-to-avoid-catastrophic-backtracking-completely
* https://github.com/NicolaasWeideman/RegexStaticAnalysis
Instead of static analysis, we may consider checking every regular expression against a few hundreds of random URLs and detect the "slow regexes" this way.
Contributor guide
No contributing guide indexed for this repository
Assessment
This issue has not been assessed yet.