unsanitized input goes to regex function leads to ReDos that make request hangs