VYPR

CWE-1333

Inefficient Regular Expression Complexity

BaseDraftLikelihood: High

Description

The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-492

CVEs mapped to this weakness (531)

page 19 of 27
  • CVE-2022-1930MedAug 22, 2022
    risk 0.31cvss 5.9epss 0.01

    An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the eth-account PyPI package, when an attacker is able to supply arbitrary input to the encode_structured_data method

  • CVE-2022-2596MedAug 1, 2022
    risk 0.31cvss 5.9epss 0.01

    Inefficient Regular Expression Complexity in GitHub repository node-fetch/node-fetch prior to 3.2.10.

  • CVE-2022-1929MedJun 2, 2022
    risk 0.31cvss 5.9epss 0.01

    An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the devcert npm package, when an attacker is able to supply arbitrary input to the certificateFor method

  • CVE-2021-43307MedJun 2, 2022
    risk 0.31cvss 5.9epss 0.02

    An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input to the test() method

  • CVE-2021-43306MedJun 2, 2022
    risk 0.31cvss 5.9epss 0.01

    An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the jquery-validation npm package, when an attacker is able to supply arbitrary input to the url2 method

  • CVE-2024-25126MedFeb 29, 2024
    risk 0.30cvss 5.3epss 0.35

    Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, leading to a possible denial of service vulnerability (ReDos 2nd degree polynomial). This vulnerability is patched in…

  • CVE-2020-5243MedFeb 21, 2020
    risk 0.30cvss 5.7epss 0.02

    uap-core before 0.7.3 is vulnerable to a denial of service attack when processing crafted User-Agent strings. Some regexes are vulnerable to regular expression denial of service (REDoS) due to overlapping capture groups. This allows remote attackers to overload a server by…

  • CVE-2023-30608MedApr 18, 2023
    risk 0.29cvss 5.5epss 0.01

    sqlparse is a non-validating SQL parser module for Python. In affected versions the SQL parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service). This issue was introduced by commit `e75e358`. The vulnerability may lead to Denial of…

  • CVE-2023-25166MedFeb 8, 2023
    risk 0.29cvss 5.5epss 0.01

    formula is a math and string formula parser. In versions prior to 3.0.1 crafted user-provided strings to formula's parser might lead to polynomial execution time and a denial of service. Users should upgrade to 3.0.1+. There are no known workarounds for this vulnerability.

  • CVE-2022-30973MedMay 31, 2022
    risk 0.29cvss 5.5epss 0.02

    We failed to apply the fix for CVE-2022-30126 to the 1.x branch in the 1.28.2 release. In Apache Tika, a regular expression in the StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted…

  • CVE-2022-30126MedMay 16, 2022
    risk 0.29cvss 5.5epss 0.03

    In Apache Tika, a regular expression in our StandardsText class, used by the StandardsExtractingContentHandler could lead to a denial of service caused by backtracking on a specially crafted file. This only affects users who are running the StandardsExtractingContentHandler,…

  • CVE-2026-77082MedAug 20, 2026
    risk 0.28cvss 4.3epss 0.00

    n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contains a regular expression denial of service (ReDoS) vulnerability in the Filter and Switch nodes, which compile user-supplied regex patterns with new RegExp() and execute them synchronously on the worker thread…

  • CVE-2026-44425MedMay 13, 2026
    risk 0.28cvss 5.4epss 0.00

    ShellHub is a centralized SSH gateway. Prior to 0.24.2, the device list endpoint accepts user-controlled identifiers in the the name field of each filter property in the base64-encoded filter query parameter and the sort_by query parameter, which are then passed directly as…

  • CVE-2026-2327MedFeb 12, 2026
    risk 0.28cvss 5.3epss 0.01

    Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the use of the regex /\*+$/ in the linkify function. An attacker can supply a long sequence of * characters followed by a non-matching…

  • CVE-2025-5342MedOct 30, 2025
    risk 0.28cvss 4.3epss 0.01

    Zohocorp ManageEngine Exchange Reporter Plus through 5721 are vulnerable to ReDOS vulnerability in the search module.

  • CVE-2025-4690MedAug 19, 2025
    risk 0.28cvss 4.3epss 0.00

    A regular expression used by AngularJS'  linky https://docs.angularjs.org/api/ngSanitize/filter/linky  filter to detect URLs in input text is vulnerable to super-linear runtime due to backtracking. With a large carefully-crafted input, this can cause a Regular expression…

  • CVE-2025-8262MedJul 28, 2025
    risk 0.28cvss 4.3epss 0.01

    A vulnerability was found in yarnpkg Yarn up to 1.22.22. It has been classified as problematic. Affected is the function explodeHostedGitFragment of the file src/resolvers/exotics/hosted-git-resolver.js. The manipulation leads to inefficient regular expression complexity. It is…

  • CVE-2025-7579MedJul 14, 2025
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in chinese-poetry 0.1. It has been rated as problematic. This issue affects some unknown processing of the file rank/server.js. The manipulation leads to inefficient regular expression complexity. The attack may be initiated remotely. The exploit has…

  • CVE-2025-7074MedJul 5, 2025
    risk 0.28cvss 4.3epss 0.01

    A vulnerability classified as problematic has been found in vercel hyper up to 3.4.1. This affects the function expand/braceExpand/ignoreMap of the file hyper/bin/rimraf-standalone.js. The manipulation leads to inefficient regular expression complexity. It is possible to…

  • CVE-2025-5892MedJun 9, 2025
    risk 0.28cvss 4.3epss 0.01

    A vulnerability, which was classified as problematic, has been found in RocketChat up to 7.6.1. This issue affects the function parseMessage of the file /apps/meteor/app/irc/server/servers/RFC2813/parseMessage.js. The manipulation of the argument line leads to inefficient…