0

Are there risks associated with using gsub on user input? Can it be used for regular expression DoS?

Anders
  • 64,406
  • 24
  • 178
  • 215
Tim Abell
  • 101
  • 3
  • 1
    Is there anything in particular you are worrid about? I think it should be safe, but what comes out on the other side should still be considered untrusted user input. – Anders Sep 10 '19 at 13:44
  • I guess DoS kind of things https://www.owasp.org/index.php/Regular_expression_Denial_of_Service_-_ReDoS – Tim Abell Sep 10 '19 at 14:18
  • 1
    Ah, I did not think of the DOS potential. Good point. I have edited your question to include that angle, feel free to roll back if you dislike the edit. – Anders Sep 10 '19 at 14:21

0 Answers0