mirror of
https://github.com/Shopify/liquid.git
synced 2026-10-03 00:55:11 -07:00
Use an atomic subgroup in range regex to avoid pathological backtracking (#1360)
This commit is contained in:
@@ -14,7 +14,10 @@ module Liquid
|
|||||||
DOUBLE_QUOTED_STRING = /\A\s*"(.*)"\s*\z/m
|
DOUBLE_QUOTED_STRING = /\A\s*"(.*)"\s*\z/m
|
||||||
INTEGERS_REGEX = /\A\s*(-?\d+)\s*\z/
|
INTEGERS_REGEX = /\A\s*(-?\d+)\s*\z/
|
||||||
FLOATS_REGEX = /\A\s*(-?\d[\d\.]+)\s*\z/
|
FLOATS_REGEX = /\A\s*(-?\d[\d\.]+)\s*\z/
|
||||||
RANGES_REGEX = /\A\s*\(\s*(\S+)\s*\.\.\s*(\S+)\s*\)\s*\z/
|
|
||||||
|
# Use an atomic group (?>...) to avoid pathological backtracing from
|
||||||
|
# malicious input as described in https://github.com/Shopify/liquid/issues/1357
|
||||||
|
RANGES_REGEX = /\A\s*\(\s*(?>(\S+)\s*\.\.)\s*(\S+)\s*\)\s*\z/
|
||||||
|
|
||||||
def self.parse(markup)
|
def self.parse(markup)
|
||||||
case markup
|
case markup
|
||||||
|
|||||||
Reference in New Issue
Block a user