{"id":"GHSA-4w5h-hx6r-28q7","summary":"ratex-parser has unbounded parser recursion that leads to stack overflow (process abort)","details":"### Summary\n\n\nRaTeX’s recursive-descent parser recurses one (or more) native stack frame per nesting level at `{`, `\\left`, `\\sqrt{`, `^{`, etc, with **no maximum depth limit**. A short, ~10 KB input of nested groups overflows the 8 MB main-thread stack and aborts the process. With `panic = \"abort\"` (`Cargo.toml:48`), and because a Rust stack overflow is always a fatal `SIGABRT` regardless of panic strategy this is an unrecoverable, whole-process denial of service reachable from a single untrusted LaTeX string.\n\n### Details\n\nThe mutual recursion has no depth guard (`crates/ratex-parser/src/parser.rs`):\n\n```\nparse_expression (:113)  -\u003e  parse_atom (:281/285)  -\u003e  parse_group (:451)\n                                  ^                          |\n                                  |   on '{' (:459) recurse  |\n                                  +--------------------------+\n```\n\n`\\left` adds another recursive edge: `handle_left` → `parse_expression` (`crates/ratex-parser/src/functions/left_right.rs:47`). The only counters present are unrelated to depth: `leftright_depth` (a `\\right`-matching counter, `parser.rs:24`) and the macro expander’s `max_expand = 1000` (`macro_expander.rs:64`), which does **not** gate brace / `\\left` recursion (those tokens never pass through `expand_once`). There is no `recursion_limit`/depth parameter on `parse_group`, `parse_expression`, or `parse_atom`.\n\n### PoC\n\n\u003cimg width=\"1097\" height=\"158\" alt=\"image\" src=\"https://github.com/user-attachments/assets/29b837a2-c455-4cb6-a055-514b31c999c6\" /\u003e\n\n\n```\n$ python3 -c 'import sys;sys.stdout.write(\"{\"*200000+\"x\"+\"}\"*200000)' | ./target/release/parse\nthread 'main' has overflowed its stack\nfatal runtime error: stack overflow, aborting\nAborted (core dumped)            # exit 134\n```\n\n(Other nesting forms work equally, e.g. `\\left(`×N, `\\sqrt{`×N, `^{`×N.)\n\n### Impact\n\nA single small request crashes the whole RaTeX process. In a typical server-side math-rendering service this is a reliable, unauthenticated DoS; on smaller worker-thread stacks (e.g. a 512 KB async runtime thread) only a few hundred bytes of nesting are required.","aliases":["CVE-2026-53531"],"modified":"2026-07-07T23:56:32.234602Z","published":"2026-07-07T23:39:30Z","database_specific":{"github_reviewed_at":"2026-07-07T23:39:30Z","nvd_published_at":null,"cwe_ids":["CWE-400","CWE-674"],"severity":"MODERATE","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/erweixin/RaTeX/security/advisories/GHSA-4w5h-hx6r-28q7"},{"type":"PACKAGE","url":"https://github.com/erweixin/RaTeX"}],"affected":[{"package":{"name":"ratex-parser","ecosystem":"crates.io","purl":"pkg:cargo/ratex-parser"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.1.11"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-4w5h-hx6r-28q7/GHSA-4w5h-hx6r-28q7.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}]}