VYPR

CWE-1333

Inefficient Regular Expression Complexity

BaseDraftLikelihood: High

Description

The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-492

CVEs mapped to this weakness (531)

page 13 of 27
  • CVE-2022-41323HigOct 16, 2022
    risk 0.42cvss 7.5epss 0.03

    In Django 3.2 before 3.2.16, 4.0 before 4.0.8, and 4.1 before 4.1.2, internationalized URLs were subject to a potential denial of service attack via the locale parameter, which is treated as a regular expression.

  • CVE-2022-37603HigOct 14, 2022
    risk 0.42cvss 7.5epss 0.02

    A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the url variable in interpolateName.js.

  • CVE-2022-37599HigOct 11, 2022
    risk 0.42cvss 7.5epss 0.02

    A Regular expression denial of service (ReDoS) flaw was found in Function interpolateName in interpolateName.js in webpack loader-utils 2.0.0 via the resourcePath variable in interpolateName.js.

  • CVE-2022-40023HigSep 7, 2022
    risk 0.42cvss 7.5epss 0.02

    Sqlalchemy mako before 1.2.2 is vulnerable to Regular expression Denial of Service when using the Lexer class to parse. This also affects babelplugin and linguaplugin.

  • CVE-2022-35923HigAug 2, 2022
    risk 0.42cvss 7.5epss 0.02

    v8n is a javascript validation library. Versions of v8n prior to 1.5.1 were found to have an inefficient regular expression complexity in the `lowercase()` and `uppercase()` regex which could lead to a denial of service attack. In testing of the `lowercase()` function a payload…

  • CVE-2022-34749HigJul 25, 2022
    risk 0.42cvss 7.5epss 0.02

    In mistune through 2.0.2, support of inline markup is implemented by using regular expressions that can involve a high amount of backtracking on certain edge cases. This behavior is commonly named catastrophic backtracking.

  • CVE-2022-31147HigJul 14, 2022
    risk 0.42cvss 7.5epss 0.02

    The jQuery Validation Plugin (jquery-validation) provides drop-in validation for forms. Versions of jquery-validation prior to 1.19.5 are vulnerable to regular expression denial of service (ReDoS) when an attacker is able to supply arbitrary input to the url2 method. This is due…

  • CVE-2022-31781HigJul 13, 2022
    risk 0.42cvss 7.5epss 0.02

    Apache Tapestry up to version 5.8.1 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles Content Types. Specially crafted Content Types may cause catastrophic backtracking, taking exponential time to complete. Specifically, this is about the…

  • CVE-2022-31129HigJul 6, 2022
    risk 0.42cvss 7.5epss 0.05

    moment is a JavaScript date library for parsing, validating, manipulating, and formatting dates. Affected versions of moment were found to use an inefficient parsing algorithm. Specifically using string-to-date parsing in moment (more specifically rfc2822 parsing, which is tried…

  • CVE-2021-46823MedJun 18, 2022
    risk 0.42cvss 6.5epss 0.02

    python-ldap before 3.4.0 is vulnerable to a denial of service when ldap.schema is used for untrusted schema definitions, because of a regular expression denial of service (ReDoS) flaw in the LDAP schema parser. By sending crafted regex input, a remote authenticated attacker…

  • CVE-2021-40660HigJun 14, 2022
    risk 0.42cvss 7.5epss 0.01

    An issue was discovered in Delight Nashorn Sandbox 0.2.0. There is an ReDoS vulnerability that can be exploited to launching a denial of service (DoS) attack.

  • CVE-2022-1510MedMay 11, 2022
    risk 0.42cvss 6.5epss 0.02

    An issue has been discovered in GitLab affecting all versions starting from 13.9 before 14.8.6, all versions starting from 14.9 before 14.9.4, all versions starting from 14.10 before 14.10.1. GitLab was not correctly handling malicious text in the CI Editor and CI Pipeline…

  • CVE-2022-24836HigApr 11, 2022
    risk 0.42cvss 7.5epss 0.04

    Nokogiri is an open source XML and HTML library for Ruby. Nokogiri `< v1.13.4` contains an inefficient regular expression that is susceptible to excessive backtracking when attempting to detect encoding in HTML documents. Users are advised to upgrade to Nokogiri `>= 1.13.4`.…

  • CVE-2022-24729MedMar 16, 2022
    risk 0.42cvss 6.5epss 0.02

    CKEditor4 is an open source what-you-see-is-what-you-get HTML editor. CKEditor4 prior to version 4.18.0 contains a vulnerability in the `dialog` plugin. The vulnerability allows abuse of a dialog input validator regular expression, which can cause a significant performance drop…

  • CVE-2022-21681HigJan 14, 2022
    risk 0.42cvss 7.5epss 0.03

    Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `inline.reflinkSearch` may cause catastrophic backtracking against some strings and lead to a denial of service (DoS). Anyone who runs untrusted markdown through a vulnerable version of…

  • CVE-2022-21680HigJan 14, 2022
    risk 0.42cvss 7.5epss 0.03

    Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `block.def` may cause catastrophic backtracking against some strings and lead to a regular expression denial of service (ReDoS). Anyone who runs untrusted markdown through a vulnerable…

  • CVE-2021-3842HigJan 4, 2022
    risk 0.42cvss 7.5epss 0.01

    nltk is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2021-41817HigJan 1, 2022
    risk 0.42cvss 7.5epss 0.03

    Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.

  • CVE-2021-23490HigDec 24, 2021
    risk 0.42cvss 7.5epss 0.02

    The package parse-link-header before 2.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the checkHeader function.

  • CVE-2021-43805HigDec 7, 2021
    risk 0.42cvss 7.5epss 0.01

    Solidus is a free, open-source ecommerce platform built on Rails. Versions of Solidus prior to 3.1.4, 3.0.4, and 2.11.13 have a denial of service vulnerability that could be exploited during a guest checkout. The regular expression used to validate a guest order's email was…