Top Stories published by Node Security in 2017

Finding and fixing ReDoS in the hapi framework

Recently a Regular Expression Denial of Service issue was reported on the content repository, a part of the hapi framework. The issue has been removed as of the writing of this post, but I can tell you that it reported a pair of regular expressions…


Pull Requests Welcome: We need your help to fix some ReDoS vulnerabilities

Recently there were a large number of regular expression denial of service ( ReDoS ) vulnerabilities released to the public via GitHub issues. These issues don’t have patches but many of the maintainers…