CVE-2022-23514: Inefficient Regular Expression Complexity in Loofah

Published Dec 13, 2022
·
Updated

Summary

Loofah < 2.19.1 contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service through CPU resource consumption.

Mitigation

Upgrade to Loofah >= 2.19.1.

Severity

The Loofah maintainers have evaluated this as High Severity 7.5 (CVSS3.1).

References

- CWE - CWE-1333: Inefficient Regular Expression Complexity (4.9) - https://hackerone.com/reports/1684163

Credit

This vulnerability was responsibly reported by @ooooooo-q (https://github.com/ooooooo-q).

Other sources

An inefficient regular expression vulnerability was found in rubygem loofah. While sanitizing certain SVG attributes, loofah is susceptible to excessive backtracking, which can result in a denial of service through CPU resource consumption.

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri. Loofah < 2.19.1 contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to sanitize certain SVG attributes. This may lead to a denial of service through CPU resource consumption. This issue is patched in version 2.19.1.

Affected Software

4 affected componentsFixes available
rubygems/loofah<2.19.1
2.19.1
redhat/rubygem-loofah<0:2.19.1-1.el8
0:2.19.1-1.el8
redhat/rubygem-loofah<2.19.1
2.19.1
Loofah Project Loofah Ruby<2.19.1

Event History

Dec 13, 2022
CVE Published
12:00 AM
Advisory Published
05:36 PM
Dec 14, 2022
CVE Published
via MITRE·01:19 PM
Data Sourced
via MITRE·01:19 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2022-23514?

CVE-2022-23514 is considered a denial of service vulnerability due to excessive CPU resource consumption.

2

How do I fix CVE-2022-23514?

To fix CVE-2022-23514, upgrade Loofah to version 2.19.1 or later.

3

What versions of Loofah are affected by CVE-2022-23514?

Loofah versions earlier than 2.19.1 are affected by CVE-2022-23514.

4

What is the impact of CVE-2022-23514?

The impact of CVE-2022-23514 can lead to a denial of service through excessive CPU usage.

5

Is CVE-2022-23514 specific to certain platforms?

CVE-2022-23514 specifically affects the Loofah Ruby gem regardless of the platform used.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203