PatchSiren cyber security CVE debrief
CVE-2026-106104 quasarframework CVE debrief
CVE-2026-106104: The Quasar Framework is vulnerable to super-linear regex backtracking on the User-Agent header, which can cause a Quasar SSR server to stall for seconds due to auto-installation of the Platform plugin. This plugin feeds the raw, unbounded User-Agent request header into a chain of backtracking regular expressions, leading to potential denial of service and increased response times. Defenders should assess potential exposure and impact, especially for high traffic or critical services.
- Vendor
- quasarframework
- Product
- quasar
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-07
- Original CVE updated
- 2026-10-07
- Advisory published
- 2026-10-07
- Advisory updated
- 2026-10-07
Who should care
Defenders responsible for Quasar SSR server deployments, especially those with high traffic or critical services, should assess potential exposure and impact due to the potential for denial of service and increased response times. They should prioritize verifying exposure and assessing potential impact on Quasar SSR server deployments.
Why it matters
Defenders should prioritize verifying exposure and assessing potential impact on Quasar SSR server deployments, especially those with high traffic or critical services, due to the potential for denial of service and increased response times.
- Potential denial of service due to stalling of Quasar SSR server
- Increased response time for requests
- Potential impact on high traffic or critical services
Technical summary
The Quasar Framework's Platform plugin is auto-installed on every server-side render and feeds the raw, unbounded User-Agent request header into a chain of backtracking regular expressions. One of these patterns contains a greedy capture followed by two unbounded .* scans, causing a crafted header to cost time proportional to the cube of its length. An 8 KB User-Agent blocks the Node.js event loop for about 4.4 seconds, and a 16 KB one for about 35 seconds. During that time, the server answers nobody, so a handful of tiny requests take an SSR site completely offline.
Defensive priority
Defenders should prioritize verifying exposure and assessing potential impact on Quasar SSR server deployments, especially those with high traffic or critical services.
Recommended defensive actions
- Verify Quasar SSR server deployments for exposure to this vulnerability
- Assess potential impact on high traffic or critical services
- Apply patches or mitigations as recommended by the vendor
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The source corpus provides details on the vulnerability, including the affected component, attack vector, and potential impact. However, it does not provide explicit information on exploitation or victim data. The vulnerability is caused by the Platform plugin's handling of the User-Agent header, which is fed into a chain of backtracking regular expressions. This can cause the server to stall for seconds, leading to potential denial of service and increased response times.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-106104 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-106104
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-106104 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106104
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Quasar Framework: Super-linear regex backtracking on User-Agent lets one request stall a Quasar
Unverified legacy reference
URL: https://storage.googleapis.com/osv-vulnerabilities/npm/GHSA-68jq-fhch-4xq4.json
osv_dev
-
Source reference
Unverified legacy reference
URL: https://github.com/quasarframework/quasar/security/advisories/GHSA-68jq-fhch-4xq4
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/quasarframework/quasar/commit/7a954ddafa756afe95c8f633f48ed68a07209d3d
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/quasarframework/quasar
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://github.com/quasarframework/quasar/releases/tag/quasar-v2.23.3
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.