Impact
The vulnerability resides in an unknown function within safe_regex.ts of the Basic Catalog component of a2ui. The function processes input that can be crafted to produce regular expressions with exponential complexity, causing excessive CPU or memory consumption. An attacker can exploit this remotely by supplying such input during.
Affected Systems
The issue affects a2ui, a project by a2ui-project, up to version 0.10.6. The vulnerability lies in the Basic Catalog component, specifically the safe_regex.ts file. Systems running any version of a2ui older than 0.10.7 are potentially exposed.
Risk and Exploitability
The CVSS score of 6.9 corresponds to a medium severity. The EPSS score of less than 1% indicates a very low likelihood that the vulnerability will be targeted in the wild. KEV catalog, suggesting it has not yet seen widespread exploitation. Since the attack can be launched remotely by supplying crafted input to the catalog rendering process, the risk is primarily in environments exposed to untrusted user input. The moderate severity combined with the low exploitation probability suggests diligent monitoring and timely patching should be sufficient for most deployments.
OpenCVE Enrichment