[ 
https://issues.apache.org/jira/browse/JEXL-471?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
 ]

Henri Biestro resolved JEXL-471.
--------------------------------
    Resolution: Fixed

Commit 
[a60740e|https://github.com/apache/commons-jexl/commit/a60740ee9f78c26d7a284eedd819de5a2fea66ee]

>  Runtime Runtime hardening: Constrain BigInteger operations and ensure regex 
> interruptibility
> ---------------------------------------------------------------------------------------------
>
>                 Key: JEXL-471
>                 URL: https://issues.apache.org/jira/browse/JEXL-471
>             Project: Commons JEXL
>          Issue Type: Bug
>    Affects Versions: 3.7.0
>            Reporter: Henri Biestro
>            Assignee: Henri Biestro
>            Priority: Major
>             Fix For: 3.7.1
>
>
> 1 — Regular expression matching should be interruptible
> Title: Regex matching in =~ operator can hang indefinitely and ignores thread 
> interruption
> Description:
> The =~ and !~ regex matching operators do not check for thread interruption 
> during pattern matching. Long-running regex operations (e.g., catastrophic 
> backtracking on pathological patterns) can hang indefinitely and cannot be 
> cancelled via Thread.interrupt(). This blocks the calling thread and prevents 
> graceful cancellation of stuck expressions.
> Fix: Wrap the matched string in InterruptibleCharSequence, which samples 
> Thread.isInterrupted() every 256 character accesses. When interrupted, throws 
> ArithmeticException("regex interrupted"), which propagates as 
> JexlException.Cancel for proper signal handling.
> 2 — BigInteger arithmetic results exceed configured precision limits
> Title: BigInteger arithmetic operations (+, -, *, /, %) not bounded by 
> MathContext precision
> Description:
> BigInteger arithmetic operations do not enforce the MathContext precision 
> limit configured on the JexlEngine, allowing results to grow unbounded. This 
> can exhaust memory or cause performance degradation. The 
> checkBigIntegerPrecision() method exists but was silently swallowed by a 
> try-catch block in add() and similar methods.
> Fix: Hoist checkBigIntegerPrecision() calls outside the coercion exception 
> handler in arithmetic methods (add(), subtract(), multiply(), etc.), so 
> precision violations surface as ArithmeticException instead of falling back 
> to string concatenation.
> 3 — Parsing huge BigInteger literals causes O(n²) DoS
> Title: BigInteger literal parsing vulnerable to algorithmic complexity DoS on 
> huge digit counts
> Description:
> The BigInteger constructor exhibits O(n²) behavior on very large digit counts 
> (millions of digits). Parsing a JEXL script containing a BigInteger literal 
> with millions of digits causes the parser to stall.
> Fix: Cap BigInteger literal digit count at parse time based on the engine's 
> MathContext.getPrecision() (or hardcoded 256-digit fallback if no precision 
> is configured). Reject literals exceeding this limit with 
> NumberFormatException, which wraps as JexlException.Parsing.



--
This message was sent by Atlassian Jira
(v8.20.10#820010)

Reply via email to