From 527fa8d6f926bb6af890e4ddef2d496194412920 Mon Sep 17 00:00:00 2001 From: "liorn-test-app[bot]" <279465434+liorn-test-app[bot]@users.noreply.github.com> Date: Sun, 12 Jul 2026 12:09:10 +0000 Subject: [PATCH] [LEGIT] Fix - js/polynomial-redos --- app/routes/profile.js | 13 +++++++++++++ 1 file changed, 13 insertions(+) diff --git a/app/routes/profile.js b/app/routes/profile.js index 9bc0557..105e597 100644 --- a/app/routes/profile.js +++ b/app/routes/profile.js @@ -41,6 +41,19 @@ function ProfileHandler (db) { // The Fix: Instead of using greedy quantifiers the same regex will work if we omit the second quantifier + // const regexPattern = /([0-9]+)\#/; const regexPattern = /[0-9]+\#/; + // Validate bankRouting input before regex to prevent DoS via excessive input length + if (typeof bankRouting !== 'string' || bankRouting.length > 50) { + return res.render("profile", { + updateError: "Bank Routing number format is invalid", + firstName, + lastName, + ssn, + dob, + address, + bankAcc, + bankRouting: '' + }); + } // Allow only numbers with a suffix of the letter #, for example: 'XXXXXX#' const testComplyWithRequirements = regexPattern.test(bankRouting); // if the regex test fails we do not allow saving