4 ms·
That's a real issue, took cloudflare down once...
by tryauuum 3mo ago
That's a real issue, took cloudflare down once...
- swiftcoder 3mo agoIt's only a real issue if it is in runtime code that parses untrusted input. 99% of the regex lints/CVEs that get flagged our way are in build-time code.
- tryauuum 3mo agoI don't fully get you. Do you mean untrusted regex or untrusted data it operates on? And to be honest, even if the regex is trusted (came from a developer) and the data as well (something predictable and structured) we are still not protected from the developer using extremely stupid regex and breaking everything