T09 · Insecure Skill Coding Practices
- Location
scripts/schema_validator.py:35- Finding
Unbounded Regular Expression Evaluation Enables Denial of Service
- Content
View full analysis
Vulnerability Details
File Location:
scripts/schema_validator.py:35-40
Vulnerability Type: Regular Expression Denial of Service (ReDoS)
Risk Level: Mediumpython # Regex if "regex" in rules and (series.dtype == object or pd.api.types.is_string_dtype(series)): pattern = re.compile(rules["regex"]) invalid = series[~series.astype(str).apply(lambda x: bool(pattern.match(x)) if pd.notna(x) else True)] if not invalid.empty: errors.append({"column": col, "error": "regex_mismatch", "count": len(invalid), "regex": rules["regex"]})Technical Analysis
SchemaValidatorcompiles a regular expression taken directly from the supplied schema and applies it to every value in the selected column. Python's standardreengine can exhibit catastrophic backtracking for ambiguous nested quantifiers, and this implementation imposes no pattern-complexity restriction, input-length limit, row limit, or matching timeout.An attacker who can control schema rules can provide a pathological expression such as
^(a+)+$. A long input consisting of repeatedacharacters followed by a nonmatching character can then require exponentially increasing CPU time. Applying the expression across many rows amplifies the resource consumption.Attack Path
- The attacker obtains the ability to submit or influence a validation schema.
- The attacker defines a pathological regular expression, such as
^(a+)+$, for a string column. - The attacker supplies one or more long values such as
"aaaaaaaa...!". - The application invokes
SchemaValidator.validate(). - Lines 37-38 compile and repeatedly evaluate the expression without a timeout.
- Catastrophic backtracking consumes excessive CPU and delays or stalls the worker process.
Impact Assessment
Successful exploitation does not grant additional system privileges, data access, or code execution. Its impact is limited to availability: an affe ...[truncated 289 chars]
- Remediation
View remediation
Remediation Suggestions
- Treat validation schemas, especially regular expressions, as trusted configuration and prevent untrusted users from supplying arbitrary patterns.
- Prefer a linear-time regular-expression engine when expressions must be user-controlled.
- If the selected engine supports deadlines, enforce a strict per-match timeout and handle timeout failures as validation errors.
- Reject oversized patterns and values before evaluation, and impose limits on the number of rows processed per request.
- Validate patterns against a restrictive allowlist and reject dangerous constructs such as ambiguous nested quantifiers.
- Consider replacing arbitrary regular expressions with predefined, reviewed validation rules for common formats.
- Add regression tests using pathological patterns and long nonmatching strings to verify that validation remains within defined CPU and latency limits.
