fix possible RegexMatchTimeoutException#1525
Merged
MaggieKimani1 merged 1 commit intomicrosoft:vnextmicrosoft/OpenAPI.NET:vnextfrom Jan 16, 2024
Merged
fix possible RegexMatchTimeoutException#1525MaggieKimani1 merged 1 commit intomicrosoft:vnextmicrosoft/OpenAPI.NET:vnextfrom
MaggieKimani1 merged 1 commit intomicrosoft:vnextmicrosoft/OpenAPI.NET:vnextfrom
Conversation
baywet
requested changes
Jan 11, 2024
Member
baywet
left a comment
There was a problem hiding this comment.
Hi @mus65,
Thanks for the contribution.
The timeout is a security requirement here. Depending on where the library is used, attackers could inject an extremely long path to DDoS a service if there was no timeout.
Instead of removing the timeout, I encourage you to explore the following route:
- replace the regex by string operations (index of, substring, etc)
- remove captures (if not necessary)
- reduce back-propagation.
e3ce8ce to
3df0b7a
Compare
Contributor
Author
3df0b7a to
0a19160
Compare
baywet
requested changes
Jan 15, 2024
Member
baywet
left a comment
There was a problem hiding this comment.
Thanks for the update, here are a few recommendations
This comment was marked as outdated.
This comment was marked as outdated.
Contributor
Author
|
@microsoft-github-policy-service agree company="TIS GmbH" |
0a19160 to
a99baf2
Compare
Member
|
@MaggieKimani1 for final review and merge |
MaggieKimani1
approved these changes
Jan 16, 2024
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
6bda890 introduced a Timeout on RegEx compilation. We hit this timeout a few times since this change.
Removed the timeout so it uses the default like before.
Stacktrace: