CWE-1333
Inefficient Regular Expression Complexity
Description
The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.
Hierarchy (View 1000)
Parents
Children
none
Related attack patterns (CAPEC)
CAPEC-492
CVEs mapped to this weakness (531)
page 14 of 27| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-3765 | Hig | 0.42 | 7.5 | 0.02 | Nov 2, 2021 | validator.js is vulnerable to Inefficient Regular Expression Complexity | ||
| CVE-2021-42836 | Hig | 0.42 | 7.5 | 0.02 | Oct 22, 2021 | GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack. | ||
| CVE-2021-3828 | Hig | 0.42 | 7.5 | 0.02 | Sep 27, 2021 | nltk is vulnerable to Inefficient Regular Expression Complexity | ||
| CVE-2021-3822 | Hig | 0.42 | 7.5 | 0.01 | Sep 27, 2021 | jsoneditor is vulnerable to Inefficient Regular Expression Complexity | ||
| CVE-2021-3820 | Hig | 0.42 | 7.5 | 0.01 | Sep 27, 2021 | inflect is vulnerable to Inefficient Regular Expression Complexity | ||
| CVE-2020-23478 | Hig | 0.42 | 7.5 | 0.01 | Sep 22, 2021 | Leo Editor v6.2.1 was discovered to contain a regular expression denial of service (ReDoS) vulnerability in the component plugins/importers/dart.py. | ||
| CVE-2021-32838 | Hig | 0.42 | 7.5 | 0.02 | Sep 20, 2021 | Flask-RESTX (pypi package flask-restx) is a community driven fork of Flask-RESTPlus. Flask-RESTX before version 0.5.1 is vulnerable to ReDoS (Regular Expression Denial of Service) in email_regex. This is fixed in version 0.5.1. | ||
| CVE-2021-3810 | Hig | 0.42 | 7.5 | 0.01 | Sep 17, 2021 | code-server is vulnerable to Inefficient Regular Expression Complexity | ||
| CVE-2021-3807 | Hig | 0.42 | 7.5 | 0.04 | Sep 17, 2021 | ansi-regex is vulnerable to Inefficient Regular Expression Complexity | ||
| CVE-2021-3804 | Hig | 0.42 | 7.5 | 0.01 | Sep 17, 2021 | taro is vulnerable to Inefficient Regular Expression Complexity | ||
| CVE-2021-3803 | Hig | 0.42 | 7.5 | 0.02 | Sep 17, 2021 | nth-check is vulnerable to Inefficient Regular Expression Complexity | ||
| CVE-2021-3795 | Hig | 0.42 | 7.5 | 0.01 | Sep 15, 2021 | semver-regex is vulnerable to Inefficient Regular Expression Complexity | ||
| CVE-2021-3794 | Hig | 0.42 | 7.5 | 0.01 | Sep 15, 2021 | vuelidate is vulnerable to Inefficient Regular Expression Complexity | ||
| CVE-2021-3777 | Hig | 0.42 | 7.5 | 0.01 | Sep 15, 2021 | nodejs-tmpl is vulnerable to Inefficient Regular Expression Complexity | ||
| CVE-2021-3749 | Hig | 0.42 | 7.5 | 0.09 | Aug 31, 2021 | axios is vulnerable to Inefficient Regular Expression Complexity | ||
| CVE-2021-32740 | Hig | 0.42 | 7.5 | 0.02 | Jul 6, 2021 | Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. An uncontrolled resource consumption vulnerability exists after version 2.3.0 through version 2.7.0. Within the URI template implementation in Addressable, a… | ||
| CVE-2020-1920 | Hig | 0.42 | 7.5 | 0.01 | Jun 1, 2021 | A regular expression denial of service (ReDoS) vulnerability in the validateBaseUrl function can cause the application to use excessive resources, become unresponsive, or crash. This was introduced in react-native version 0.59.0 and fixed in version 0.64.1. | ||
| CVE-2021-33502 | Hig | 0.42 | 7.5 | 0.02 | May 24, 2021 | The normalize-url package before 4.5.1, 5.x before 5.3.1, and 6.x before 6.0.1 for Node.js has a ReDoS (regular expression denial of service) issue because it has exponential performance for data: URLs. | ||
| CVE-2021-27291 | Hig | 0.42 | 7.5 | 0.04 | Mar 17, 2021 | In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a… | ||
| CVE-2021-28092 | Hig | 0.42 | 7.5 | 0.02 | Mar 12, 2021 | The is-svg package 2.1.0 through 4.2.1 for Node.js uses a regular expression that is vulnerable to Regular Expression Denial of Service (ReDoS). If an attacker provides a malicious string, is-svg will get stuck processing the input for a very long time. |
- risk 0.42cvss 7.5epss 0.02
validator.js is vulnerable to Inefficient Regular Expression Complexity
- risk 0.42cvss 7.5epss 0.02
GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.
- risk 0.42cvss 7.5epss 0.02
nltk is vulnerable to Inefficient Regular Expression Complexity
- risk 0.42cvss 7.5epss 0.01
jsoneditor is vulnerable to Inefficient Regular Expression Complexity
- risk 0.42cvss 7.5epss 0.01
inflect is vulnerable to Inefficient Regular Expression Complexity
- risk 0.42cvss 7.5epss 0.01
Leo Editor v6.2.1 was discovered to contain a regular expression denial of service (ReDoS) vulnerability in the component plugins/importers/dart.py.
- risk 0.42cvss 7.5epss 0.02
Flask-RESTX (pypi package flask-restx) is a community driven fork of Flask-RESTPlus. Flask-RESTX before version 0.5.1 is vulnerable to ReDoS (Regular Expression Denial of Service) in email_regex. This is fixed in version 0.5.1.
- risk 0.42cvss 7.5epss 0.01
code-server is vulnerable to Inefficient Regular Expression Complexity
- risk 0.42cvss 7.5epss 0.04
ansi-regex is vulnerable to Inefficient Regular Expression Complexity
- risk 0.42cvss 7.5epss 0.01
taro is vulnerable to Inefficient Regular Expression Complexity
- risk 0.42cvss 7.5epss 0.02
nth-check is vulnerable to Inefficient Regular Expression Complexity
- risk 0.42cvss 7.5epss 0.01
semver-regex is vulnerable to Inefficient Regular Expression Complexity
- risk 0.42cvss 7.5epss 0.01
vuelidate is vulnerable to Inefficient Regular Expression Complexity
- risk 0.42cvss 7.5epss 0.01
nodejs-tmpl is vulnerable to Inefficient Regular Expression Complexity
- risk 0.42cvss 7.5epss 0.09
axios is vulnerable to Inefficient Regular Expression Complexity
- risk 0.42cvss 7.5epss 0.02
Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. An uncontrolled resource consumption vulnerability exists after version 2.3.0 through version 2.7.0. Within the URI template implementation in Addressable, a…
- risk 0.42cvss 7.5epss 0.01
A regular expression denial of service (ReDoS) vulnerability in the validateBaseUrl function can cause the application to use excessive resources, become unresponsive, or crash. This was introduced in react-native version 0.59.0 and fixed in version 0.64.1.
- risk 0.42cvss 7.5epss 0.02
The normalize-url package before 4.5.1, 5.x before 5.3.1, and 6.x before 6.0.1 for Node.js has a ReDoS (regular expression denial of service) issue because it has exponential performance for data: URLs.
- risk 0.42cvss 7.5epss 0.04
In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a…
- risk 0.42cvss 7.5epss 0.02
The is-svg package 2.1.0 through 4.2.1 for Node.js uses a regular expression that is vulnerable to Regular Expression Denial of Service (ReDoS). If an attacker provides a malicious string, is-svg will get stuck processing the input for a very long time.