{"id":"GHSA-x4hg-hfwf-p9mw","summary":"@asymmetric-effort/nogginlessdom vulnerable to ReDoS via user-controlled regex in HTMLInputElement pattern validation","details":"## Summary\n\nThe `HTMLInputElement.checkValidity()` method constructed a `RegExp` directly from the user-controlled `pattern` property without any sanitization or timeout protection. This allowed an attacker to inject a regex with catastrophic backtracking, freezing the event loop.\n\n## Fix\n\nFixed in commit https://github.com/asymmetric-effort/NogginLessDom/commit/25a3cbac665fae5663f8b71c073b80c3152dbe7b on `main`. Added:\n- Pattern length limit (1024 characters)\n- Nested quantifier detection (`hasNestedQuantifiers`) that rejects patterns like `(a+)+` before constructing the regex\n- Patterns exceeding limits are treated as non-matching (safe default)","modified":"2026-09-10T03:50:53.053866960Z","published":"2026-07-02T20:20:04Z","database_specific":{"cwe_ids":["CWE-1333"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2026-07-02T20:20:04Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/asymmetric-effort/NogginLessDom/security/advisories/GHSA-x4hg-hfwf-p9mw"},{"type":"WEB","url":"https://github.com/asymmetric-effort/NogginLessDom/commit/25a3cbac665fae5663f8b71c073b80c3152dbe7b"},{"type":"PACKAGE","url":"https://github.com/asymmetric-effort/NogginLessDom"}],"affected":[{"package":{"name":"@asymmetric-effort/nogginlessdom","ecosystem":"npm","purl":"pkg:npm/%40asymmetric-effort/nogginlessdom"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.0.22"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 0.0.21","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-x4hg-hfwf-p9mw/GHSA-x4hg-hfwf-p9mw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N"}]}