[
https://issues.apache.org/jira/browse/JEXL-471?page=com.atlassian.jira.plugin.system.issuetabpanels:all-tabpanel
]
Henri Biestro resolved JEXL-471.
--------------------------------
Resolution: Fixed
Commit
[a60740e|https://github.com/apache/commons-jexl/commit/a60740ee9f78c26d7a284eedd819de5a2fea66ee]
> Runtime Runtime hardening: Constrain BigInteger operations and ensure regex
> interruptibility
> ---------------------------------------------------------------------------------------------
>
> Key: JEXL-471
> URL: https://issues.apache.org/jira/browse/JEXL-471
> Project: Commons JEXL
> Issue Type: Bug
> Affects Versions: 3.7.0
> Reporter: Henri Biestro
> Assignee: Henri Biestro
> Priority: Major
> Fix For: 3.7.1
>
>
> 1 — Regular expression matching should be interruptible
> Title: Regex matching in =~ operator can hang indefinitely and ignores thread
> interruption
> Description:
> The =~ and !~ regex matching operators do not check for thread interruption
> during pattern matching. Long-running regex operations (e.g., catastrophic
> backtracking on pathological patterns) can hang indefinitely and cannot be
> cancelled via Thread.interrupt(). This blocks the calling thread and prevents
> graceful cancellation of stuck expressions.
> Fix: Wrap the matched string in InterruptibleCharSequence, which samples
> Thread.isInterrupted() every 256 character accesses. When interrupted, throws
> ArithmeticException("regex interrupted"), which propagates as
> JexlException.Cancel for proper signal handling.
> 2 — BigInteger arithmetic results exceed configured precision limits
> Title: BigInteger arithmetic operations (+, -, *, /, %) not bounded by
> MathContext precision
> Description:
> BigInteger arithmetic operations do not enforce the MathContext precision
> limit configured on the JexlEngine, allowing results to grow unbounded. This
> can exhaust memory or cause performance degradation. The
> checkBigIntegerPrecision() method exists but was silently swallowed by a
> try-catch block in add() and similar methods.
> Fix: Hoist checkBigIntegerPrecision() calls outside the coercion exception
> handler in arithmetic methods (add(), subtract(), multiply(), etc.), so
> precision violations surface as ArithmeticException instead of falling back
> to string concatenation.
> 3 — Parsing huge BigInteger literals causes O(n²) DoS
> Title: BigInteger literal parsing vulnerable to algorithmic complexity DoS on
> huge digit counts
> Description:
> The BigInteger constructor exhibits O(n²) behavior on very large digit counts
> (millions of digits). Parsing a JEXL script containing a BigInteger literal
> with millions of digits causes the parser to stall.
> Fix: Cap BigInteger literal digit count at parse time based on the engine's
> MathContext.getPrecision() (or hardcoded 256-digit fallback if no precision
> is configured). Reject literals exceeding this limit with
> NumberFormatException, which wraps as JexlException.Parsing.
--
This message was sent by Atlassian Jira
(v8.20.10#820010)