Exploiting Input Sanitization for Regex Denial of Service
Efe Barlas, Xin Du, James C. Davis
Abstract
Web services use server-side input sanitization to guard against harmful input. Some web services publish their sanitization logic to make their client interface more usable, e.g., allowing clients to debug invalid requests locally. However, this usability practice poses a security risk. Specifically, services may share the regexes they use to sanitize input strings -and regex-based denial of service (ReDoS) is an emerging threat. Although prominent service outages caused by ReDoS have spurred interest in this topic, we know little about the degree to which live web services are vulnerable to ReDoS. In this paper, we conduct the first black-box study measuring the extent of ReDoS vulnerabilities in live web services. We apply the Consistent Sanitization Assumption: that client-side sanitization logic, including regexes, is consistent with the sanitization logic on the server-side. We identify a service's regex-based input sanitization in its HTML forms or its API, find vulnerable regexes among these regexes, craft ReDoS probes, and pinpoint vulnerabilities. We analyzed the HTML forms of 1,000 services and the APIs of 475 services. Of these, 355 services publish regexes; 17 services publish unsafe regexes; and 6 services are vulnerable to ReDoS through their APIs (6 domains; 15 subdomains). Both Microsoft and Amazon Web Services patched their web services as a result of our disclosure. Since these vulnerabilities were from API specifications, not HTML forms, we proposed a ReDoS defense for a popular API validation library, and our patch has been merged. To summarize: in client-visible sanitization logic, some web services advertise Re-DoS vulnerabilities in plain sight. Our results motivate short-term patches and long-term fundamental solutions.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 222e1df2-171f-41c7-b7e6-d7d613db293fCited by top-tier papers10
- AGORA: Automated Generation of Test Oracles for REST APIsJuan C. Alonso, Sergio Segura, Antonio Ruiz-CortésISSTA 2023 · 15 citations
- Black Ostrich: Web Application Scanning with String SolversBenjamin Eriksson, Amanda Stjerna, Riccardo De Masellis, Philipp Rümmer et al.CCS 2023 · 9 citations
- Towards an Effective Method of ReDoS Detection for Non-backtracking EnginesWeihao Su, Hong Huang, Rongchen Li, Haiming Chen et al.USENIX Security 2024 · 4 citations
- Interleaved Bitstream Execution for Multi-Pattern Regex Matching on GPUsTianao Ge, Xiaowen Chu, Hongyuan LiuMICRO 2025 · 4 citations
- Towards Efficient Matching of Regexes with Backreferences using Register Set AutomataVojtech Havlena, Lukás Holík, Ondrej Lengál, Jan Vasák et al.PLDI 2026
Builds on16
- SlowFuzz: Automated Domain-Independent Detection of Algorithmic Complexity VulnerabilitiesTheofilos Petsios, Jason Zhao, Angelos D. Keromytis, Suman JanaCCS 2017 · 214 citations
- Freezing the Web: A Study of ReDoS Vulnerabilities in JavaScript-based Web ServersCristian-Alexandru Staicu, Michael PradelUSENIX Security 2018 · 125 citations
- Wrex: A Unified Programming-by-Example Interaction for Synthesizing Readable Code for Data ScientistsIan Drosos, Titus Barik, Philip J. Guo, Robert DeLine et al.CHI 2020 · 110 citations
- Multi-modal synthesis of regular expressionsQiaochu Chen, Xinyu Wang, Xi Ye, Greg Durrett et al.PLDI 2020 · 81 citations
- Intelligent REST API data fuzzingPatrice Godefroid, Bo-Yuan Huang, Marina PolishchukFSE 2020 · 57 citations
Related papers
- Improving Developers' Understanding of Regex Denial of Service Tools through Anti-Patterns and Fix StrategiesSk Adnan Hassan, Zainab Aamir, Dongyoon Lee, James C. Davis et al.S&P 2023
- Runtime Recovery of Web Applications under Zero-Day ReDoS AttacksZhihao Bai, Ke Wang, Hang Zhu, Yinzhi Cao et al.S&P 2021 · 19 citations
- ReDoSHunter: A Combined Static and Dynamic Approach for Regular Expression DoS DetectionYeting Li, Zixuan Chen, Jialun Cao, Zhiwu Xu et al.USENIX Security 2021 · 20 citations
- RegexScalpel: Regular Expression Denial of Service (ReDoS) Defense by Localize-and-FixYeting Li, Yecheng Sun, Zhiwu Xu, Jialun Cao et al.USENIX Security 2022
- Using Selective Memoization to Defeat Regular Expression Denial of Service (ReDoS)James C. Davis, Francisco Servant, Dongyoon LeeS&P 2021 · 43 citations
