AdguardTeam / AdguardTeam/FiltersCompiler
Protection from ReDos
- Lenguaje dominante
- JavaScript
- Estrellas
- 64
- Forks
- 11
- Métricas de merge de PR
- Sin PR fusionados en 30 d
Descripción
Check this issue:
https://github.com/AdguardTeam/AdguardBrowserExtension/issues/2240
The point is that a poor regular expression may cause the extension to completely break the browser.
I suggest adding more checks for regular expressions in the filtering rules.
More on catastrophic backtracking and relevant articles:
* https://javascript.info/regexp-catastrophic-backtracking#back-to-words-and-strings
* https://api7.ai/blog/how-to-avoid-catastrophic-backtracking-completely
* https://github.com/NicolaasWeideman/RegexStaticAnalysis
Instead of static analysis, we may consider checking every regular expression against a few hundreds of random URLs and detect the "slow regexes" this way.
Guía de contribución
No hay ninguna guía de contribución indexada para este repositorio
Evaluación
Este issue todavía no se ha evaluado.