Files
codeql/python/ql/test/query-tests/Security/CWE-730-PolynomialReDoS/test.py
2021-07-15 14:15:44 +02:00

10 lines
240 B
Python

import re
from flask import Flask, request
app = Flask(__name__)
@app.route("/poly-redos")
def code_execution():
text = request.args.get("text")
re.sub(r"^\s+|\s+$", "", text) # NOT OK
re.match(r"^0\.\d+E?\d+$", text) # NOT OK