NicolaasWeideman / RegexStaticAnalysis
A tool to perform static analysis on regexes to determine whether they are vulnerable to ReDoS.
☆110Updated 2 years ago
Alternatives and similar repositories for RegexStaticAnalysis:
Users that are interested in RegexStaticAnalysis are comparing it to the libraries listed below
- ☆143Updated 2 years ago
- An automated tool for the detection of regexes' slow-matching vulnerabilities.☆155Updated 3 years ago
- Detect vulnerable regexes in your project. REDOS, catastrophic backtracking.☆319Updated 3 years ago
- Instrumentation framework for Node.js compliant to ECMAScript 2020 based on GraalVM.☆53Updated this week
- Type Analyzer for JavaScript☆194Updated 4 years ago
- A list of ReDoS vulnerabilities in npm modules found by the Software Lab at TU Darmstadt. For each vulnerability, there is a proof-of-con…☆58Updated 7 years ago
- Performant taint analysis for Node.js☆49Updated 5 months ago
- Codyze is a static analyzer for Java, C, C++ based on code property graphs☆88Updated this week
- WALA analyses and tools that are implemented in JavaScript☆82Updated 8 years ago
- Vulnerabilities discovered in npm packages [Berkeley PL & Security Research]☆43Updated 6 months ago
- Generic SAST Library☆126Updated 2 months ago
- A Dynamic Symbolic Execution (DSE) engine for JavaScript. ExpoSE is highly scalable, compatible with recent JavaScript standards, and sup…☆193Updated this week
- Creates a CFG from JavaScript source code.☆68Updated 4 months ago
- ☆29Updated 3 months ago
- Automatically Preventing Code Injection Attacks on Node.js☆78Updated 2 years ago
- Plume is a code representation benchmarking library with options to extract the AST from Java bytecode and store the result in various gr…☆73Updated 3 months ago
- A static analysis API for finding deserialization attack gadgets☆38Updated 2 years ago
- Parser utility to generate ASTs from PHP source code suitable to be processed by Joern.☆35Updated 4 years ago
- The official repo of Doop, the declarative pointer analysis framework.☆169Updated 2 months ago
- TaintFlow, a framework for JavaScript dynamic information flow analysis.☆17Updated 2 years ago
- ReDoSHunter: A Combined Static and Dynamic Approach for Regular Expression DoS Detection☆78Updated 2 years ago
- A dynamic symbolic analysis tool for Java☆116Updated 5 years ago
- A delta debugger for JavaScript☆51Updated 2 years ago
- Parser utility to generate ASTs from PHP source code suitable to be processed by Joern.☆16Updated 5 years ago
- Towards Measuring Supply Chain Attacks on Package Managers for Interpreted Languages☆127Updated 2 years ago
- Phosphor: Dynamic Taint Tracking for the JVM☆170Updated 3 weeks ago
- Securibench Micro is a benchmark for static analysis tools for security.☆26Updated 6 years ago
- Security contract types☆60Updated 2 years ago
- JAW: A Graph-based Security Analysis Framework for Client-side JavaScript☆105Updated last month
- SARIF Microsoft Visual Studio Code extension☆113Updated 3 months ago