{"id":"GHSA-455v-w7r9-3vv9","summary":"Cattown is Vulnerable to Uncontrolled Resource Consumption through Inefficient Regular Expression Complexity","details":"### Overview\nA security review of the Cattown identified multiple weaknesses that could potentially impact its stability and security.\n\n### Affected Versions\n- All versions below 1.0.2\n\n### Description of Vulnerabilities\n1. CWE-1333: Inefficient Regular Expression Complexity\nThe package used regular expressions with inefficient, potentially exponential worst-case complexity. This can cause excessive CPU usage due to excessive backtracking on crafted inputs, potentially leading to denial of service.\n2. CWE-400: Uncontrolled Resource Consumption (Resource Exhaustion)\nThe package was vulnerable to resource exhaustion, where processing malicious inputs could cause high CPU or memory usage, potentially leading to denial of service.\n\n### Impact\n- Trigger excessive CPU consumption leading to denial of service\n- Cause resource exhaustion affecting service availability\n- Bypass protection mechanisms causing unexpected or insecure behavior\n\n### Resolution\nThese vulnerabilities have been fixed in version 1.0.2 of the Cattown. Users are strongly encouraged to upgrade to this version to mitigate the risks.\n\n### Recommendations\n- Upgrade to Cattown version 1.0.2 or later as soon as possible.\n- Review and restrict input sources if untrusted inputs are processed.\n\n### Acknowledgments\nThe issues were proactively identified through CodeQL static analysis.","aliases":["CVE-2025-58451"],"modified":"2025-09-25T21:44:20Z","published":"2025-09-09T20:44:25Z","database_specific":{"cwe_ids":["CWE-1333","CWE-400"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2025-09-09T20:44:25Z","nvd_published_at":"2025-09-08T22:15:34Z"},"references":[{"type":"WEB","url":"https://github.com/IEatUranium238/Cattown/security/advisories/GHSA-455v-w7r9-3vv9"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-58451"},{"type":"WEB","url":"https://github.com/IEatUranium238/Cattown/commit/70c2a28fb7dc520cfb7e401e0e141bff3dd26ead"},{"type":"PACKAGE","url":"https://github.com/IEatUranium238/Cattown"},{"type":"WEB","url":"https://github.com/IEatUranium238/Cattown/releases/tag/security"},{"type":"WEB","url":"https://www.npmjs.com/package/cattown"}],"affected":[{"package":{"name":"cattown","ecosystem":"npm","purl":"pkg:npm/cattown"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.0.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-455v-w7r9-3vv9/GHSA-455v-w7r9-3vv9.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}