Regex ReDoS Vulnerability Detector

Regex ReDoS Vulnerability Detector MCP Connector for Claude

A+

Detects catastrophic backtracking and ReDoS vulnerabilities in regular expression patterns using deterministic structural analysis.

3 tools Official Updated Oct 1, 2026 Official Vinkius Partner

The Regex ReDoS Vulnerability Detector is a specialized security utility designed to identify Regular Expression Denial of Service (ReDoS) vulnerabilities. By performing deterministic meta-parsing, it scans for high-risk structural patterns such as nested quantifiers and overlapping alternations that trigger catastrophic backtracking in engines like V8. This tool provides developers with precise identification of vulnerable substrings and actionable remediation strategies to prevent event loop freezing in Node.js environments.

redossecurityregexvulnerabilitybacktrackingnodejs

3 tools expose this connector's capabilities to your AI agent.

detect_structural_features

Scans a regex pattern for structural vulnerabilities

generate_remediation_report

Generates a detailed remediation report for regex vulnerabilities

evaluate_security_posture

Evaluates the security risk of detected regex features

See how to talk to your AI agent using Regex ReDoS Vulnerability Detector.

Analyze this regex pattern for ReDoS risks: `(a+)+$`

The pattern `(a+)+$` contains a nested quantifier, which is a high-risk feature. The `detect_structural_features` tool identifies this as a 'nested_quantifier' hazard, leading to a high risk score due to potential catastrophic backtracking.

Check the security posture for these features: ['overlapping_alternation']

The `evaluate_security_posture` tool determines that while an overlapping alternation is present, the overall risk score remains moderate. The pattern is not classified as 'isSafe: false' unless high-complexity nesting is also detected.

Generate a report for the regex `(a|b|ab)*` with features ['overlapping_alternation']

The `generate_remediation_report` tool identifies the substring `(a|b|ab)*` as vulnerable. It recommends refactoring the alternation to avoid overlapping branches that cause redundant engine checks.

The `detect_structural_features` tool uses deterministic meta-parsing to inspect the string structure. It identifies hazardous constructs like nested quantifiers (e.g., `(a+)+`) by analyzing the arrangement of characters and symbols without actually attempting a match against a subject string, thus avoiding any risk of triggering the vulnerability itself.

Related Connectors