Impact
Vendure’s public Shop GraphQL API accepted user‑supplied regular expression patterns through the StringOperators.regex field. On SQLite and sqljs backends the raw pattern was executed synchronously by the Node.js event loop, allowing an unauthenticated caller to supply a catastrophically backtracking expression. A single nested‑quantifier pattern could block request processing long enough to halt the storefront and admin API, and repeated requests could sustain a denial‑of‑service event loop.
Affected Systems
These findings apply to Vendure HQ’s headless commerce platform, specifically versions prior to 3.6.5. The vulnerability exists when using SQLite or the bundled sqljs backend; deployments on PostgreSQL, MySQL, or MariaDB are unaffected.
Risk and Exploitability
The CVSS score reflects a high impact for denial of service, with a base score of 7.5. EPSS data is not available, and the issue is not listed in the CISA KEV catalog. An attacker needs only to authenticate? false; the vulnerability is fully unauthenticated, simply constructing a malicious GraphQL query containing a backtracking regex via the regex operator. Should the attacker succeed, the target’s event loop will stall, rendering the public and private APIs unusable until the request completes or is forcibly terminated. The absence of an exploit in common attack suites and the lack of a KEV listing suggest moderate exploitation risk, but the high severity warrants rapid remediation.
OpenCVE Enrichment
Github GHSA