{"id":"CVE-2021-43805","details":"Solidus is a free, open-source ecommerce platform built on Rails. Versions of Solidus prior to 3.1.4, 3.0.4, and 2.11.13 have a denial of service vulnerability that could be exploited during a guest checkout. The regular expression used to validate a guest order's email was subject to exponential backtracking through a fragment like `a.a.` Versions 3.1.4, 3.0.4, and 2.11.13 have been patched to use a different regular expression. The maintainers added a check for email addresses that are no longer valid that will print information about any affected orders that exist. If a prompt upgrade is not an option, a workaround is available. It is possible to edit the file `config/application.rb` manually (with code provided by the maintainers in the GitHub Security Advisory) to check email validity.","aliases":["GHSA-qxmr-qxh6-2cc9"],"modified":"2026-07-09T10:52:42.583461Z","published":"2021-12-07T18:15:07.407Z","references":[{"type":"FIX","url":"https://github.com/solidusio/solidus/commit/9867153e01e3c3b898cdbcedd7b43375ea922401"},{"type":"EVIDENCE","url":"https://github.com/solidusio/solidus/security/advisories/GHSA-qxmr-qxh6-2cc9"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/solidusio/solidus","events":[{"introduced":"0"},{"fixed":"310872fde2d6e44241aea0eedb686a3119c53393"},{"introduced":"a731a1a7bede0b7cd012551c27ebdd74e08c022a"},{"fixed":"14e9ccda302f3ed22af3b7caae007586cdd0576a"},{"introduced":"1e06d430ba17c8ac092ddb00f23b38eb5c062b80"},{"fixed":"c8b6357ffee9a969f7939e6dcf865508c8a623f8"},{"fixed":"9867153e01e3c3b898cdbcedd7b43375ea922401"}],"database_specific":{"cpe":"cpe:2.3:a:nebulab:solidus:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.11.13"},{"introduced":"3.0.0"},{"fixed":"3.0.4"},{"introduced":"3.1.0"},{"fixed":"3.1.4"}],"source":["CPE_RANGE","REFERENCES"]}}],"versions":["v2.11.12","v3.0.3","v3.1.3","v2.11.11","v3.0.2","v3.1.2","v3.1.1","v3.1.0","v2.11.10","v3.0.1","v3.0.0","v2.11.9","v2.11.8","v2.11.7","v2.11.6","v2.11.5","v3.0.0.rc2","v2.11.4","v2.11.3","v2.11.2","v2.11.1","v2.11.0","v2.10.0.beta1","v2.9.0.rc.1","v2.7.0","v2.0.0.beta1","v1.1.0.pre2","v1.1.0.beta1","v1.0.0.pre3","v1.0.0.pre2","v1.0.0.pre"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-43805.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}