Disclosure summary
### Summary One unauthenticated request with a crafted `User-Agent` stalls a Quasar SSR server for seconds. Quasar auto-installs its `Platform` plugin on every server-side render, and `Platform.parseSSR()` feeds the raw, unbounded `User-Agent` request header into a chain of backtracking regular expressions in `getMatch()`. One of those patterns contains a greedy capture followed by two unbounded `.*` scans, so a crafted header costs time proportional to the cube of its length. An 8 KB `User-Agent` blocks the Node.js event loop for about 4.4 seconds, and a 16 KB one for about 35 seconds. During that time the server answers nobody, so a handful of tiny requests take an SSR site completely offline. ### Details `Platform` is in the `autoInstalledPlugins` array in `ui/src/install-quasar.js`, so it is installed unconditionally by `app.use(Quasar, ...)`. The generated SSR entry (`app-vite/templates/entry/app.js`, called from `app-vite/templates/entry/server-entry.js`) runs that for every HTTP request, and it runs before routing, so requests to paths that do not exist are affected too. On the server the plugin takes the header verbatim (`ui/src/plugins/platform/Platform.js`): ```js Platfor
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-68jq-fhch-4xq4
Open original source · Updated Oct 07, 2026
Quasar Framework: Super-linear regex backtracking on User-Agent lets one request stall a Quasar SSR server
Source severity: HIGH / 8.7
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| npm | quasar | 2.23.3 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2026-10-07T12:14:31-04:00
MODIFIED 2026-10-07T12:14:32-04:00
INGESTED 2026-10-08T12:05:11-04:00