davisjam / vuln-regex-detector

Detect vulnerable regexes in your project. REDOS, catastrophic backtracking.
MIT License
320 stars 29 forks source link

Missed vulns #48

Closed davisjam closed 6 years ago

davisjam commented 6 years ago

Detectors miss:

  1. /a+$/ is vulnerable but detectors miss it.
  2. /a{1,100}a{1,100}a{1,100}$/ is vulnerable but detectors time out.