Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

ReDoS is a bug in the regex engine. Still, V8 etc. seem to refuse to provide a ReDoS-safe regex engine by default.


Is the possibility to write an infinite loop in your language of choice a bug?


Most regex usage actually doesnt require near infinite backtracking, so limited unless opted in wouldn’t be that weird.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: