{"id":"GHSA-hp68-xhvj-x6j6","summary":"jsx-slack insufficient patch for CVE-2021-43838 ReDoS","details":"We found the patch for CVE-2021-43838 in jsx-slack v4.5.1 is insufficient to save from Regular Expression Denial of Service (ReDoS) attack.\n\nThis vulnerability affects to jsx-slack v4.5.1 and earlier versions.\n\n### Impact\n\nIf attacker can put a lot of JSX elements into `\u003cblockquote\u003e` tag _with including multibyte characters_, an internal regular expression for escaping characters may consume an excessive amount of computing resources.\n\n```javascript\n/** @jsxImportSource jsx-slack */\nimport { Section } from 'jsx-slack'\n\nconsole.log(\n  \u003cSection\u003e\n    \u003cblockquote\u003e\n      {[...Array(40)].map(() =\u003e (\n        \u003cp\u003e亜\u003c/p\u003e\n      ))}\n    \u003c/blockquote\u003e\n  \u003c/Section\u003e\n)\n```\n\nv4.5.1 has released by passing the test against ASCII characters but missed the case of multibyte characters.\nhttps://github.com/yhatt/jsx-slack/security/advisories/GHSA-55xv-f85c-248q\n\n### Patches\n\njsx-slack v4.5.2 has updated regular expressions for escaping blockquote characters to prevent catastrophic backtracking. It is also including an updated test case to confirm rendering multiple tags in `\u003cblockquote\u003e` with multibyte characters.\n\n### References\n\n- https://github.com/yhatt/jsx-slack/commit/46bc88391d89d5fda4ce689e18ca080bcdd29ecc\n\n### Credits\n\nThanks to @hieki for finding out this vulnerability.","aliases":["CVE-2021-43843"],"modified":"2026-02-04T02:28:11.199784Z","published":"2022-01-06T18:34:18Z","related":["CVE-2021-43843"],"database_specific":{"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2022-01-04T20:19:23Z","nvd_published_at":"2021-12-20T22:15:00Z","cwe_ids":["CWE-400"]},"references":[{"type":"WEB","url":"https://github.com/yhatt/jsx-slack/security/advisories/GHSA-55xv-f85c-248q"},{"type":"WEB","url":"https://github.com/yhatt/jsx-slack/security/advisories/GHSA-hp68-xhvj-x6j6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2021-43843"},{"type":"WEB","url":"https://github.com/yhatt/jsx-slack/commit/46bc88391d89d5fda4ce689e18ca080bcdd29ecc"},{"type":"WEB","url":"https://github.com/yhatt/jsx-slack/releases/tag/v4.5.2"},{"type":"WEB","url":"https://github.com/yhatt/jsx-slack/security"}],"affected":[{"package":{"name":"jsx-slack","ecosystem":"npm","purl":"pkg:npm/jsx-slack"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.5.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/01/GHSA-hp68-xhvj-x6j6/GHSA-hp68-xhvj-x6j6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"}]}