
ReDoS explorando backtracking em regex, resultando em consumo excessivo de CPU e negação de serviço (DoS) em aplicações Node.js.
Vulnerability: CVE-2025-25200
Type: Regular Expression Denial of Service (ReDoS)
Component: Kao >= 2.0.0, < 2.15.4 , >= 3.0.0-alpha.0, < 3.0.0-alpha.3 , >= 1.0.0, < 1.7.1, < 0.21.2
Description: This vulnerability presents quadratic time complexity O(n²) or, in more critical scenarios, exponential O(2ⁿ), meaning the time required to process the input grows with its size (backtracking). The origin of the problem lies in the mechanism of the regular expression engine called backtracking. When the input (token) does not match, the engine simply retreats to previous positions where it could choose an alternative path.
This vulnerability was handled following responsible disclosure practices.