hardBackend

What is a ReDoS (Regular Expression Denial of Service) attack and how do you avoid it?

1.0k views
01

Understand the problem

Catastrophic backtracking blocking the event loop.

nodejssecurityredosregex
02

Attempt it yourself

Sketch your approach before reading the solution — that's what interviews test.

Stuck? AI Nudge Available

Get a conceptual hint to guide your logic without spoiling the final implementation.

03

Study the solution

The solution is waiting

Give it an honest attempt first — then compare your thinking with the full walkthrough.

04

Read the code

Risky pattern → safer approach
// ❌ catastrophic backtracking on "aaaaaaaaaaaaaaaa!"
const evil = /^(a+)+$/;

// ✅ simple linear pattern + input cap
if (input.length > 256) throw new Error('input too long');
const safe = /^a+$/;

// ✅ or use RE2 for untrusted input (no backtracking)
// import RE2 from 're2'; new RE2('(a+)+$').test(input);
05

Join the discussion

Discussion (0)

Sign in to join the discussion.

No responses yet. Be the first to share what you think.