{"id":"GHSA-x4hg-hfwf-p9mw","title":"@asymmetric-effort/nogginlessdom vulnerable to ReDoS via user-controlled regex in HTMLInputElement pattern validation","summary":"@asymmetric-effort/nogginlessdom vulnerable to ReDoS via user-controlled regex in HTMLInputElement pattern validation","severity":"medium","cwe":["CWE-1333"],"vendor":"asymmetric-effort","product":"@asymmetric-effort/nogginlessdom","ecosystem":"npm","affected":["@asymmetric-effort/nogginlessdom <= 0.0.21"],"patched":["@asymmetric-effort/nogginlessdom 0.0.22"],"published":"2026-07-02","updated":"2026-07-02","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-x4hg-hfwf-p9mw","references":[{"url":"https://github.com/asymmetric-effort/NogginLessDom/security/advisories/GHSA-x4hg-hfwf-p9mw"},{"url":"https://github.com/asymmetric-effort/NogginLessDom/commit/25a3cbac665fae5663f8b71c073b80c3152dbe7b"},{"url":"https://github.com/advisories/GHSA-x4hg-hfwf-p9mw"}],"tags":["ghsa","npm"],"ingestedAt":"2026-07-02T20:42:45.648Z","slug":"GHSA-x4hg-hfwf-p9mw","body":"## Overview\n\n## Summary\n\nThe `HTMLInputElement.checkValidity()` method constructed a `RegExp` directly from the user-controlled `pattern` property without any sanitization or timeout protection. This allowed an attacker to inject a regex with catastrophic backtracking, freezing the event loop.\n\n## Fix\n\nFixed in commit https://github.com/asymmetric-effort/NogginLessDom/commit/25a3cbac665fae5663f8b71c073b80c3152dbe7b on `main`. Added:\n- Pattern length limit (1024 characters)\n- Nested quantifier detection (`hasNestedQuantifiers`) that rejects patterns like `(a+)+` before constructing the regex\n- Patterns exceeding limits are treated as non-matching (safe default)\n\n## Affected packages\n\n- `@asymmetric-effort/nogginlessdom <= 0.0.21`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `@asymmetric-effort/nogginlessdom 0.0.22`","depth":"sunlit","depthScore":28,"depthScoreParts":{"impact":27.5,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}