PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-106104 quasarframework CVE debrief

CVE-2026-106104: The Quasar Framework is vulnerable to super-linear regex backtracking on the User-Agent header, which can cause a Quasar SSR server to stall for seconds due to auto-installation of the Platform plugin. This plugin feeds the raw, unbounded User-Agent request header into a chain of backtracking regular expressions, leading to potential denial of service and increased response times. Defenders should assess potential exposure and impact, especially for high traffic or critical services.

Vendor
quasarframework
Product
quasar
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-07
Original CVE updated
2026-10-07
Advisory published
2026-10-07
Advisory updated
2026-10-07

Who should care

Defenders responsible for Quasar SSR server deployments, especially those with high traffic or critical services, should assess potential exposure and impact due to the potential for denial of service and increased response times. They should prioritize verifying exposure and assessing potential impact on Quasar SSR server deployments.

Why it matters

Defenders should prioritize verifying exposure and assessing potential impact on Quasar SSR server deployments, especially those with high traffic or critical services, due to the potential for denial of service and increased response times.

  • Potential denial of service due to stalling of Quasar SSR server
  • Increased response time for requests
  • Potential impact on high traffic or critical services

Technical summary

The Quasar Framework's Platform plugin is auto-installed on every server-side render and feeds the raw, unbounded User-Agent request header into a chain of backtracking regular expressions. One of these patterns contains a greedy capture followed by two unbounded .* scans, causing a crafted header to cost time proportional to the cube of its length. An 8 KB User-Agent blocks the Node.js event loop for about 4.4 seconds, and a 16 KB one for about 35 seconds. During that time, the server answers nobody, so a handful of tiny requests take an SSR site completely offline.

Defensive priority

Defenders should prioritize verifying exposure and assessing potential impact on Quasar SSR server deployments, especially those with high traffic or critical services.

Recommended defensive actions

  • Verify Quasar SSR server deployments for exposure to this vulnerability
  • Assess potential impact on high traffic or critical services
  • Apply patches or mitigations as recommended by the vendor
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The source corpus provides details on the vulnerability, including the affected component, attack vector, and potential impact. However, it does not provide explicit information on exploitation or victim data. The vulnerability is caused by the Platform plugin's handling of the User-Agent header, which is fed into a chain of backtracking regular expressions. This can cause the server to stall for seconds, leading to potential denial of service and increased response times.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-106104 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-106104

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-106104 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-106104

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.