ReDOS in URL query string obfuscation
Summary
A regular expression used to obfuscate URL query strings can consume excessive CPU when processing certain attacker-controlled input. This can stall request processing and cause denial of service in applications using affected HTTP tracing integrations.
Details
The default query-string obfuscation pattern can exhibit excessive backtracking. The pattern is applied synchronously when recording HTTP URL metadata, allowing query-string processing to occupy application resources for an extended period.
As a workaround, set DD_TRACE_OBFUSCATION_QUERY_STRING_REGEXP to the fixed regex below, then restart the application.
```...
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| dd-trace npm | >= 5.131.0, < 5.131.1 | 5.131.1 |
| >= 6.0.0, < 6.20.1 | 6.20.1 |
Details and references
### Summary A regular expression used to obfuscate URL query strings can consume excessive CPU when processing certain attacker-controlled input. This can stall request processing and cause denial of service in applications using affected HTTP tracing integrations. ### Details The default query-string obfuscation pattern can exhibit excessive backtracking. The pattern is applied synchronously when recording HTTP URL metadata, allowing query-string processing to occupy application resources for an extended period. As a workaround, set DD_TRACE_OBFUSCATION_QUERY_STRING_REGEXP to the fixed regex below, then restart the application. ``` DD_TRACE_OBFUSCATION_QUERY_STRING_REGEXP='(?:(?:"|%22)?)(?:(?:old[-_]?|new[-_]?)?p(?:ass)?w(?:or)?d(?:1|2)?|pass(?:[-_]?phrase)?|secret|(?:api[-_]?|private[-_]?|public[-_]?|access[-_]?|secret[-_]?|app(?:lication)?[-_]?)key(?:[-_]?id)?|token|consumer[-_]?(?:id|key|secret)|sign(?:ed|ature)?|auth(?:entication|orization)?)(?:(?:\s|%20)*(?:=|%3D)[^&]+|(?:"|%22)(?:\s|%20)*(?::|%3A)(?:\s|%20)*(?:"|%22)(?:%2[^2]|%[^2]|[^"%])+(?:"|%22))|(?:bearer(?:\s|%20)+[a-z0-9._\-]+|token(?::|%3A)[a-z0-9]{13}|gh[opsu]_[0-9a-zA-Z]{36}|(?:(?<![\w-])|(?<=%[0-9a-f]{2}))ey[I-L][\w-]+(?:=|%3D)*\.ey[I-L][\w-]+(?:=|%3D)*(?:\.(?:[\w.+/=-]|%3D|%2F|%2B)+)?|-{5}BEGIN(?:[a-z\s]|%20)+PRIVATE(?:\s|%20)KEY-{5}[^\-]+-{5}END(?:[a-z\s]|%20)+PRIVATE(?:\s|%20)KEY(?:-{5})?(?:\n|%0A)?|(?:ssh-(?:rsa|dss)|ecdsa-[a-z0-9]+-[a-z0-9]+)(?:\s|%20|%09)+(?:[a-z0-9/.+]|%2F|%5C|%2B){100,}(?:=|%3D)*(?:(?:\s|%20|%09)+[a-z0-9._-]+)?)' ``` ### Proof of concept Detailed triggering inputs and reproduction steps are omitted from this advisory. The patched version includes regression coverage for the affected behavior. ### Impact Regular expression denial of service (ReDoS) affecting applications that process attacker-controlled URL query strings through the vulnerable obfuscation pattern. Successful exploitation can cause excessive CPU consumption, prolonged request latency, and service unavailability. The vulnerable processing is enabled by default for affected HTTP integrations that include query strings in URL span tags.
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- Severity from
- GitHub (reviewed advisory)