AdguardTeam / AdguardTeam/FiltersCompiler
Protection from ReDos
- 主要语言
- JavaScript
- 星标
- 64
- 派生
- 11
- PR 合并指标
- 30 天内没有已合并 PR
描述
Check this issue:
https://github.com/AdguardTeam/AdguardBrowserExtension/issues/2240
The point is that a poor regular expression may cause the extension to completely break the browser.
I suggest adding more checks for regular expressions in the filtering rules.
More on catastrophic backtracking and relevant articles:
* https://javascript.info/regexp-catastrophic-backtracking#back-to-words-and-strings
* https://api7.ai/blog/how-to-avoid-catastrophic-backtracking-completely
* https://github.com/NicolaasWeideman/RegexStaticAnalysis
Instead of static analysis, we may consider checking every regular expression against a few hundreds of random URLs and detect the "slow regexes" this way.
贡献指南
这个仓库没有索引到贡献指南
评估
这个 Issue 还没有评估数据。