Regex Debugging

Regex Catastrophic Backtracking Guide

Recognize and remove catastrophic regex backtracking caused by ambiguous nested repetition, overlapping alternatives and long near-miss inputs. Last updated September 29, 2026.

Recognize and remove catastrophic regex backtracking caused by ambiguous nested repetition, overlapping alternatives and long near-miss inputs. This reference is written for developers who need practical validation behavior, reviewable rules and safe examples rather than copied snippets with no explanation.

Recommended workflow

StepWhy it matters
Find repeated ambiguityLook for nested quantifiers and alternatives that can consume the same text in many ways.
Test near-missesUse long input that almost matches and measure growth with strict time limits.
Rewrite deterministicallyRemove overlap, anchor boundaries and use atomic or possessive constructs only when supported.
Add operational guardsLimit input length and execution time where untrusted patterns or text are accepted.

Starter snippet

risk: (a+)+$   safer: ^a+$

Review checks

Common mistakes

Validation should help users correct input while protecting systems from bad data. Keep syntax checks, product policy, security review and deliverability checks separate.

Related Formalint references

Continue with Regex Performance Guide, Regex Greedy vs Lazy Quantifiers, Safe Online Dev Tools.