StackOverflow had a similar case a while back: https://stackstatus.net/post/147710624694/outage-postmortem-...
* Google's RE2 https://github.com/google/re2/wiki/WhyRE2
* https://github.com/laurikari/tre/
There is a good series of articles about the problem: https://swtch.com/~rsc/regexp/regexp3.html
I would strongly recommend deploying such a regular expression matcher to avoid problems like this. There are examples in the above article that you can use to test anything in your production deployment that accepts regular expressions to see how well it copes.
Regular languages have some very nice properties relating to how they can be evaluated. Some regular expression engines have features that pulls the expressions from being a regular language into more complexity.