PT-2025-7071 · Npm · @Octokit/Plugin-Paginate-Rest
Shiyubanzhou
·
Published
2025-02-14
·
Updated
2026-06-04
·
CVE-2025-25288
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions:
@octokit/plugin-paginate-rest versions 1.0.0 through 11.4.1
Description:
The issue is a Regular Expression Denial of Service (ReDoS) vulnerability that can be triggered when calling
octokit.paginate.iterator() with a specially crafted octokit instance, particularly with a malicious link parameter in the headers section of the request. This can cause high CPU utilization and even service slowdowns or freezes when processing specially crafted Link headers. The vulnerability occurs due to excessive backtracking in the regex pattern /<([^>]+)>;s*rel="next"/.Recommendations:
For versions prior to 11.4.1, update to version 11.4.1 to resolve the issue.
As a temporary workaround, consider restricting the use of the
octokit.paginate.iterator() function until a patch is available.
Avoid using the link parameter in the headers section of the request until the issue is resolved.Exploit
Fix
DoS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Octokit/Plugin-Paginate-Rest