VYPR

CWE-1333

Inefficient Regular Expression Complexity

BaseDraftLikelihood: High

Description

The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-492

CVEs mapped to this weakness (531)

page 14 of 27
  • CVE-2021-3765HigNov 2, 2021
    risk 0.42cvss 7.5epss 0.02

    validator.js is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2021-42836HigOct 22, 2021
    risk 0.42cvss 7.5epss 0.02

    GJSON before 1.9.3 allows a ReDoS (regular expression denial of service) attack.

  • CVE-2021-3828HigSep 27, 2021
    risk 0.42cvss 7.5epss 0.02

    nltk is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2021-3822HigSep 27, 2021
    risk 0.42cvss 7.5epss 0.01

    jsoneditor is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2021-3820HigSep 27, 2021
    risk 0.42cvss 7.5epss 0.01

    inflect is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2020-23478HigSep 22, 2021
    risk 0.42cvss 7.5epss 0.01

    Leo Editor v6.2.1 was discovered to contain a regular expression denial of service (ReDoS) vulnerability in the component plugins/importers/dart.py.

  • CVE-2021-32838HigSep 20, 2021
    risk 0.42cvss 7.5epss 0.02

    Flask-RESTX (pypi package flask-restx) is a community driven fork of Flask-RESTPlus. Flask-RESTX before version 0.5.1 is vulnerable to ReDoS (Regular Expression Denial of Service) in email_regex. This is fixed in version 0.5.1.

  • CVE-2021-3810HigSep 17, 2021
    risk 0.42cvss 7.5epss 0.01

    code-server is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2021-3807HigSep 17, 2021
    risk 0.42cvss 7.5epss 0.04

    ansi-regex is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2021-3804HigSep 17, 2021
    risk 0.42cvss 7.5epss 0.01

    taro is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2021-3803HigSep 17, 2021
    risk 0.42cvss 7.5epss 0.02

    nth-check is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2021-3795HigSep 15, 2021
    risk 0.42cvss 7.5epss 0.01

    semver-regex is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2021-3794HigSep 15, 2021
    risk 0.42cvss 7.5epss 0.01

    vuelidate is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2021-3777HigSep 15, 2021
    risk 0.42cvss 7.5epss 0.01

    nodejs-tmpl is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2021-3749HigAug 31, 2021
    risk 0.42cvss 7.5epss 0.09

    axios is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2021-32740HigJul 6, 2021
    risk 0.42cvss 7.5epss 0.02

    Addressable is an alternative implementation to the URI implementation that is part of Ruby's standard library. An uncontrolled resource consumption vulnerability exists after version 2.3.0 through version 2.7.0. Within the URI template implementation in Addressable, a…

  • CVE-2020-1920HigJun 1, 2021
    risk 0.42cvss 7.5epss 0.01

    A regular expression denial of service (ReDoS) vulnerability in the validateBaseUrl function can cause the application to use excessive resources, become unresponsive, or crash. This was introduced in react-native version 0.59.0 and fixed in version 0.64.1.

  • CVE-2021-33502HigMay 24, 2021
    risk 0.42cvss 7.5epss 0.02

    The normalize-url package before 4.5.1, 5.x before 5.3.1, and 6.x before 6.0.1 for Node.js has a ReDoS (regular expression denial of service) issue because it has exponential performance for data: URLs.

  • CVE-2021-27291HigMar 17, 2021
    risk 0.42cvss 7.5epss 0.04

    In pygments 1.1+, fixed in 2.7.4, the lexers used to parse programming languages rely heavily on regular expressions. Some of the regular expressions have exponential or cubic worst-case complexity and are vulnerable to ReDoS. By crafting malicious input, an attacker can cause a…

  • CVE-2021-28092HigMar 12, 2021
    risk 0.42cvss 7.5epss 0.02

    The is-svg package 2.1.0 through 4.2.1 for Node.js uses a regular expression that is vulnerable to Regular Expression Denial of Service (ReDoS). If an attacker provides a malicious string, is-svg will get stuck processing the input for a very long time.