VYPR
High severity7.5NVD Advisory· Published May 17, 2022· Updated Jun 17, 2026

CVE-2022-26650

CVE-2022-26650

Description

In Apache ShenYui, ShenYu-Bootstrap, RegexPredicateJudge.java uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where both parameters are controllable by the user. This can cause an attacker pass in malicious regular expressions and characters causing a resource exhaustion. This issue affects Apache ShenYu (incubating) 2.4.0, 2.4.1 and 2.4.2 and is fixed in 2.4.3.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.apache.shenyu:shenyuMaven
>= 2.4.0, < 2.4.32.4.3
org.apache.shenyu:shenyu-bootstrapMaven
>= 2.4.0, < 2.4.32.4.3

Affected products

3

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.