Impact
DotVVM’s routing parsing can trigger catastrophic regular‑expression backtracking when a URL contains many unconstrained parameters in a single path segment. A remote attacker can supply a long, near‑matching path that causes the .NET regex engine to consume excessive CPU time, potentially exhausting server resources and causing the application to become unresponsive. The vulnerability is classified as CWE‑1333, a regular expression denial of service flaw.
Affected Systems
The affected product is the open‑source DotVVM framework from riganti. Versions earlier than 4.2.11, 4.3.15, and 5.0.0‑preview09‑final are susceptible. The issue is fixed in those releases by adding a timeout and, where supported, using the .NET non‑backtracking regex engine, which limits the attack surface.
Risk and Exploitability
The flaw has a CVSS score of 8.2, indicating a high likelihood of successful exploitation. EPSS score is < 1%, and the vulnerability is not yet listed in the CISA KEV catalog. Attackers can exploit it remotely from the public internet by crafting URLs that trigger regex evaluation without needing any authentication or special privileges. The available mitigation, a timeout or engine switch, reduces the risk by preventing prolonged backtracking, but the vulnerability remains severe until a patch is applied.
OpenCVE Enrichment