fix: prevent public key validation ReDoS - #1417
Merged
Merged
Conversation
🦋 Changeset detectedLatest commit: 8bfbf89 The changes in this PR will be included in the next version bump. This PR includes changesets to release 6 packages
Not sure what this means? Click here to learn what changesets are. Click here if you're a maintainer who wants to add another changeset to this PR |
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
dannyhw
marked this pull request as ready for review
July 27, 2026 22:32
Collaborator
Author
|
@MikitasK can you take a look? |
dannyhw
marked this pull request as draft
July 27, 2026 22:36
dannyhw
marked this pull request as ready for review
July 27, 2026 22:37
This was referenced Jul 28, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
@callstack/repackRoot cause
The existing
\s*[\s\S]+?\s*expression allowed the JavaScript regex engine to partition an internal whitespace run in many ways before failing to find the PEM footer. BecauseScriptLocator.publicKeycan come from resolver-provided runtime metadata and had no length bound, malformed input could block the JavaScript thread with polynomial backtracking.This addresses code-scanning alert #10 (
js/polynomial-redos).Compatibility and impact
The replacement is language-equivalent to the previous validator: both accept any non-empty content between the existing
BEGIN PUBLIC KEYandEND PUBLIC KEYmarkers after trimming. The public API, normalization, errors, native verification, and accepted input set are unchanged. Matching malformed near-misses is now linear.No migration or user action is required.
Test plan
pnpm --filter @callstack/repack test -- --watchman=false ScriptManager.test.tspnpm --filter @callstack/repack typecheckpnpm biome check packages/repack/src/modules/ScriptManager/normalizePublicKey.ts packages/repack/src/modules/ScriptManager/__tests__/ScriptManager.test.ts