fix: resolve ReDoS vulnerability in safe_name regex (CodeQL rb/polynomial-redos) - #6
Draft
theworker02 with Copilot wants to merge 2 commits into
Draft
fix: resolve ReDoS vulnerability in safe_name regex (CodeQL rb/polynomial-redos)#6theworker02 with Copilot wants to merge 2 commits into
theworker02 with Copilot wants to merge 2 commits into
Conversation
Copilot
AI
changed the title
[WIP] Fix code scanning alert(s) flagged in repository
fix: resolve ReDoS vulnerability in safe_name regex (CodeQL rb/polynomial-redos)
Aug 3, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes CodeQL alert #1: the
-+\zsub-expression insafe_nameallowed O(n²) backtracking on strings with many consecutive hyphens, enabling a denial-of-service via crafted input.Summary
safe_namestripped leading/trailing hyphens using/\A-+|-+\z/. The-+\zbranch is ambiguous — the engine retries the quantifier from every hyphen position before failing, giving quadratic worst-case time. Replaced both-+branches with the possessive quantifier-++, which never gives back already-consumed characters:Possessive quantifiers are supported in Ruby's Oniguruma engine across all supported versions. Output is identical for all valid inputs.
Verification
bundle exec rake testbundle exec rubocopCompatibility
Tested on Ruby 3.2.3 (x86_64-linux). Possessive quantifiers (
++) are available in Oniguruma (used by MRI) since Ruby 1.9.