<rss version="2.0"><channel><title>Regular Expressions on CRS Project</title><link>https://0d2d0d50.website-1u6.pages.dev/tags/regular-expressions/</link><description>Recent content in CRS Project</description><item><title>Regular Expression DoS weaknesses in CRS</title><link>https://0d2d0d50.website-1u6.pages.dev/20190425/regular-expression-dos-weaknesses-in-crs/</link><pubDate>Thu, 25 Apr 2019 15:29:15 +0200</pubDate><description>&lt;p&gt;Somdev Sangwan has discovered several Regular Expression Denial of Service (ReDoS) weaknesses in the rules provided by the CRS project. They are listed under the following CVEs:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11387"&gt;CVE-2019–11387&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11388"&gt;CVE-2019–11388&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://nvd.nist.gov/vuln/detail/CVE-2019-11389"&gt;CVE-2019–11389&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11390"&gt;CVE-2019–11390&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a href="https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-11391"&gt;CVE-2019–11391&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The fact that CRS is affected by ReDoS is not particularly surprising and truth be told, we knew that was the case. We just have not solved it yet - or have not been able to solve it yet.&lt;/p&gt;</description></item></channel></rss>