chatwoot is vulnerable to Inefficient Regular Expression Complexity
The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.
Link | Tags |
---|---|
https://huntr.dev/bounties/1625088985607-chatwoot/chatwoot | issue tracking patch exploit third party advisory |
https://github.com/chatwoot/chatwoot/commit/aa7db90cd2d23dbcf22a94f1e4c100dd909e2172 | third party advisory patch |