Glossary

ReDoS (regular expression denial of service)

A regex that takes exponential time on input that almost matches.

Some regular expressions backtrack catastrophically. A pattern with a quantifier applied to an already-quantified group, such as (a+)+$, has exponentially many ways to divide the input, and on a string that nearly matches the engine may try them one after another. Even modest input can make a browser tab unresponsive, with the exact threshold depending on the engine, pattern and hardware.

What makes this dangerous in a browser is that regex execution cannot be interrupted. There is no timeout option, and a time check between matches never runs, because the engine never returns control during a single match attempt. The page simply stops responding.

This tester rejects some suspicious patterns before execution and limits input size, but a heuristic cannot identify every expensive expression. Do not treat acceptance as proof of safety. Other designs can use a time-limited worker that can be terminated, or a non-backtracking engine with a restricted feature set; those protections are not the same as a timer around a synchronous match.