Description
DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, a route containing multiple unconstrained parameters in one path segment can cause excessive regular-expression backtracking in DotvvmRoute.IsMatch when a remote requester supplies a long near-match path. DotvvmRouteParser.RouteRegex previously had no matching timeout. Patched runtimes retry with the .NET non-backtracking engine, while runtimes that do not support non-backtracking matching return HTTP 503 after the one-second timeout in DotvvmRoutingMiddleware. This issue is fixed in versions 4.2.11, 4.3.15, and 5.0.0-preview09-final.
Published: 2026-09-14
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Denial of Service
Action: Immediate Patch
AI Analysis

Impact

DotVVM’s routing parsing can trigger catastrophic regular‑expression backtracking when a URL contains many unconstrained parameters in a single path segment. A remote attacker can supply a long, near‑matching path that causes the .NET regex engine to consume excessive CPU time, potentially exhausting server resources and causing the application to become unresponsive. The vulnerability is classified as CWE‑1333, a regular expression denial of service flaw.

Affected Systems

The affected product is the open‑source DotVVM framework from riganti. Versions earlier than 4.2.11, 4.3.15, and 5.0.0‑preview09‑final are susceptible. The issue is fixed in those releases by adding a timeout and, where supported, using the .NET non‑backtracking regex engine, which limits the attack surface.

Risk and Exploitability

The flaw has a CVSS score of 8.2, indicating a high likelihood of successful exploitation. EPSS score is < 1%, and the vulnerability is not yet listed in the CISA KEV catalog. Attackers can exploit it remotely from the public internet by crafting URLs that trigger regex evaluation without needing any authentication or special privileges. The available mitigation, a timeout or engine switch, reduces the risk by preventing prolonged backtracking, but the vulnerability remains severe until a patch is applied.

Generated by OpenCVE AI on September 20, 2026 at 23:06 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade DotVVM to version 4.2.11, 4.3.15, or 5.0.0‑preview09‑final, which implement a one‑second timeout and use the non‑backtracking .NET regex engine.
  • If an upgrade is not immediately possible, configure the web server or reverse proxy to reject request paths longer than a reasonable limit (e.g., 4–5 KB) before the request reaches DotVVM, thereby preventing excessive regex processing.
  • Implement explicit route constraints or simplify complex route patterns so that each path segment contains bounds or length limits, reducing the chance of catastrophic backtracking even if the underlying regex engine is not upgraded.

Generated by OpenCVE AI on September 20, 2026 at 23:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 17 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Riganti
Riganti dotvvm
Vendors & Products Riganti
Riganti dotvvm

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, a route containing multiple unconstrained parameters in one path segment can cause excessive regular-expression backtracking in DotvvmRoute.IsMatch when a remote requester supplies a long near-match path. DotvvmRouteParser.RouteRegex previously had no matching timeout. Patched runtimes retry with the .NET non-backtracking engine, while runtimes that do not support non-backtracking matching return HTTP 503 after the one-second timeout in DotvvmRoutingMiddleware. This issue is fixed in versions 4.2.11, 4.3.15, and 5.0.0-preview09-final.
Title DotVVM: ReDOS in routing
Weaknesses CWE-1333
References
Metrics cvssV4_0

{'score': 8.2, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T17:54:30.539Z

Reserved: 2026-06-24T18:49:56.208Z

Link: CVE-2026-57577

cve-icon Vulnrichment

Updated: 2026-09-14T17:54:25.683Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T18:17:57.353

Modified: 2026-09-30T19:57:08.043

Link: CVE-2026-57577

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:15:04Z

Weaknesses
  • CWE-1333

    Inefficient Regular Expression Complexity