A 20-minute ReDoS audit for a Node API you already shipped
Every regex in your request path is code with a runtime that depends on the input, and unlike the rest of your code, nobody ever asked what its worst case is. That is the whole vulnerability. Not obsc
devholster.hashnode.dev5 min read