The Greedy Regex — JavaScript Bug Hunt
Inspired by Cloudflare's 2019 global outage — a single greedy regex in the WAF pinned every CPU on the edge.
- Language: JavaScript
- Layer: Backend
- Difficulty: Medium
- Concepts: Regex, Parsing
- Modelled on: Cloudflare · 2019
- Visible tests: the first assignment wins; value keeps everything after the first equals; tokens with invalid keys are skipped
- Reward: 50 XP for a complete fix
Briefing
Inspired by Cloudflare's 2019 global outage — a single greedy regex in the WAF pinned every CPU on the edge. Beyond the meltdown, greedy patterns are just wrong-answer machines.
ruleParser.js extracts the FIRST key=value token from a firewall rule line. The shipped pattern grabs the wrong things.
Bug report
BUG-WAF-711 · Priority: Critical · Reported by: edge team
extractAssignment(line) spec:
- scan whitespace-separated tokens; the first token containing "=" wins
- key = the part before the FIRST "=", value = everything after it
- keys are lowercase letters/underscores only, else keep scanning
- no such token -> null
Observed: on "score=5 action=block", the greedy pattern returns key "score=5 action" value "block".
Logs
[waf] parse("score=5 action=block") -> { key: "score=5 action", value: "block" }The code as shipped
src/waf/ruleParser.js (editable)
// Extracts the first key=value assignment from a rule line.
exports.extractAssignment = function (line) {
var m = line.match(/(.*)=(.*)/);
if (!m) return null;
return { key: m[1], value: m[2] };
};
Open the hunt to edit the files, run the visible tests and submit against the hidden ones. More JavaScript bug hunts.