---
id: GHSA-x4hg-hfwf-p9mw
title: >-
  @asymmetric-effort/nogginlessdom vulnerable to ReDoS via user-controlled regex
  in HTMLInputElement pattern validation
summary: >-
  @asymmetric-effort/nogginlessdom vulnerable to ReDoS via user-controlled regex
  in HTMLInputElement pattern validation
severity: medium
cwe:
  - CWE-1333
vendor: asymmetric-effort
product: '@asymmetric-effort/nogginlessdom'
ecosystem: npm
affected:
  - '@asymmetric-effort/nogginlessdom <= 0.0.21'
patched:
  - '@asymmetric-effort/nogginlessdom 0.0.22'
published: '2026-07-02'
updated: '2026-07-02'
source: GHSA
sourceUrl: 'https://github.com/advisories/GHSA-x4hg-hfwf-p9mw'
references:
  - url: >-
      https://github.com/asymmetric-effort/NogginLessDom/security/advisories/GHSA-x4hg-hfwf-p9mw
  - url: >-
      https://github.com/asymmetric-effort/NogginLessDom/commit/25a3cbac665fae5663f8b71c073b80c3152dbe7b
  - url: 'https://github.com/advisories/GHSA-x4hg-hfwf-p9mw'
tags:
  - ghsa
  - npm
ingestedAt: '2026-07-02T20:42:45.648Z'
---

## Overview

## Summary

The `HTMLInputElement.checkValidity()` method constructed a `RegExp` directly from the user-controlled `pattern` property without any sanitization or timeout protection. This allowed an attacker to inject a regex with catastrophic backtracking, freezing the event loop.

## Fix

Fixed in commit https://github.com/asymmetric-effort/NogginLessDom/commit/25a3cbac665fae5663f8b71c073b80c3152dbe7b on `main`. Added:
- Pattern length limit (1024 characters)
- Nested quantifier detection (`hasNestedQuantifiers`) that rejects patterns like `(a+)+` before constructing the regex
- Patterns exceeding limits are treated as non-matching (safe default)

## Affected packages

- `@asymmetric-effort/nogginlessdom <= 0.0.21`

## Remediation

Upgrade to a patched release:

- `@asymmetric-effort/nogginlessdom 0.0.22`
