Guide
Avoiding Catastrophic Regex Backtracking
Recognize ambiguous nested repetition and put practical bounds around regex work.
Reviewed against the listed primary reference and synthetic local workflow; this is not a runtime or security certification.
Related tools
The debugging problem
Some patterns explore many equivalent partitions before rejecting an input. A short success sample can conceal a severe slowdown on a longer near miss.
A practical sequence
- Identify nested quantifiers over overlapping alternatives.
- Try a gradually longer synthetic near miss and observe time.
- Replace ambiguous repetition with a narrower grammar or parser.
- Enforce input length and worker time limits at the application boundary.
Synthetic example
Risky shape: (a+)+$
Near miss: aaaaaaaaaaaaaaaa!
Safer approach: define the accepted token sequence explicitly.A failure to watch for
A timeout implemented with Promise.race on the main thread cannot interrupt synchronous regex execution; use a worker that can be terminated.
Limits and interpretation
No simple static rule detects every pathological regex. Runtime bounds and representative tests remain necessary.
References
FAQ
What should I verify first when using this avoiding catastrophic regex backtracking workflow?
Identify nested quantifiers over overlapping alternatives.
What can this workflow not prove?
No simple static rule detects every pathological regex. Runtime bounds and representative tests remain necessary.