PT-2026-94344 · Vendure · Vendure
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Vendure versions prior to 3.6.5
Description
An unauthenticated Regular Expression Denial of Service (ReDoS) exists in the public Shop GraphQL API. The issue occurs when the
StringOperators.regex filter is used, as the raw pattern is passed to a synchronous SQLite user-defined function (UDF) that executes within the Node.js event loop. An attacker can provide a catastrophically backtracking pattern—such as one containing nested quantifiers—to block the event loop, making the storefront and admin API unavailable. This specifically affects deployments using the better-sqlite3 or sqljs database drivers. The ShopProductsResolver.products resolver is publicly accessible, allowing this attack to be triggered without authentication. PostgreSQL, MySQL, and MariaDB deployments are not affected as they do not execute this regular expression in the Node.js event loop.Recommendations
Update to version 3.6.5.
As a temporary mitigation, restrict access to the
ShopProductsResolver.products resolver to authenticated users only if anonymous browsing is not required.Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vendure