The Greedy Regex — JavaScript Bug Hunt

Inspired by Cloudflare's 2019 global outage — a single greedy regex in the WAF pinned every CPU on the edge.

  • Language: JavaScript
  • Layer: Backend
  • Difficulty: Medium
  • Concepts: Regex, Parsing
  • Modelled on: Cloudflare · 2019
  • Visible tests: the first assignment wins; value keeps everything after the first equals; tokens with invalid keys are skipped
  • Reward: 50 XP for a complete fix

Briefing

Inspired by Cloudflare's 2019 global outage — a single greedy regex in the WAF pinned every CPU on the edge. Beyond the meltdown, greedy patterns are just wrong-answer machines.

ruleParser.js extracts the FIRST key=value token from a firewall rule line. The shipped pattern grabs the wrong things.

Bug report

BUG-WAF-711 · Priority: Critical · Reported by: edge team

extractAssignment(line) spec:

  • scan whitespace-separated tokens; the first token containing "=" wins
  • key = the part before the FIRST "=", value = everything after it
  • keys are lowercase letters/underscores only, else keep scanning
  • no such token -> null

Observed: on "score=5 action=block", the greedy pattern returns key "score=5 action" value "block".

Logs

[waf] parse("score=5 action=block") -> { key: "score=5 action", value: "block" }

The code as shipped

src/waf/ruleParser.js (editable)

// Extracts the first key=value assignment from a rule line.
exports.extractAssignment = function (line) {
  var m = line.match(/(.*)=(.*)/);
  if (!m) return null;
  return { key: m[1], value: m[2] };
};

Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More JavaScript bug hunts.