AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-106104.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 8.7CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 07, 2026

Disclosure summary

### Summary One unauthenticated request with a crafted `User-Agent` stalls a Quasar SSR server for seconds. Quasar auto-installs its `Platform` plugin on every server-side render, and `Platform.parseSSR()` feeds the raw, unbounded `User-Agent` request header into a chain of backtracking regular expressions in `getMatch()`. One of those patterns contains a greedy capture followed by two unbounded `.*` scans, so a crafted header costs time proportional to the cube of its length. An 8 KB `User-Agent` blocks the Node.js event loop for about 4.4 seconds, and a 16 KB one for about 35 seconds. During that time the server answers nobody, so a handful of tiny requests take an SSR site completely offline. ### Details `Platform` is in the `autoInstalledPlugins` array in `ui/src/install-quasar.js`, so it is installed unconditionally by `app.use(Quasar, ...)`. The generated SSR entry (`app-vite/templates/entry/app.js`, called from `app-vite/templates/entry/server-entry.js`) runs that for every HTTP request, and it runs before routing, so requests to paths that do not exist are affected too. On the server the plugin takes the header verbatim (`ui/src/plugins/platform/Platform.js`): ```js Platfor

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-68jq-fhch-4xq4

Open original source · Updated Oct 07, 2026

Quasar Framework: Super-linear regex backtracking on User-Agent lets one request stall a Quasar SSR server

Source severity: HIGH / 8.7

EcosystemPackageAffected rangeFirst patched
npmquasar2.23.3

Original records & references

PUBLISHED 2026-10-07T12:14:31-04:00
MODIFIED 2026-10-07T12:14:32-04:00
INGESTED 2026-10-08T12:05:11-04:00