Описание
Svelte is a performance oriented web framework. From version 5.51.5 to before version 5.55.7, an internal regex in the Svelte runtime can take exponential time to test in <svelte:element this={tag}></svelte:element>. This issue has been patched in version 5.55.7.
A flaw was found in Svelte, a web framework. An internal regular expression (regex) in the Svelte runtime, specifically when processing <svelte:element this={tag}></svelte:element>, can be exploited by a remote attacker. By providing specially crafted input, an attacker can cause the regex to take an exponential amount of time to process, leading to a Regular Expression Denial of Service (ReDoS) condition. This can make the affected application unresponsive or unavailable to legitimate users.
Отчет
A flaw was found in Svelte. An internal regex in the Svelte runtime can take exponential time when processing specially crafted input in <svelte:element this={tag}> elements, leading to a Regular Expression Denial of Service (ReDoS). Red Hat products that ship svelte (Podman Desktop, Konflux) use it as a UI framework and do not expose user-controlled input to the vulnerable regex path in production.
Меры по смягчению последствий
Upgrade to Svelte 5.55.7 or later.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Build of Podman Desktop | rh-podman-desktop.git | Fix deferred | ||
| Red Hat Build of Podman Desktop - Tech Preview | rhdesktop/rh-podman-desktop-ext-bootc-rhel10 | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
5.9 Medium
CVSS3
Связанные уязвимости
Svelte is a performance oriented web framework. From version 5.51.5 to before version 5.55.7, an internal regex in the Svelte runtime can take exponential time to test in <svelte:element this={tag}></svelte:element>. This issue has been patched in version 5.55.7.
EPSS
5.9 Medium
CVSS3