VYPR

CWE-1333

Inefficient Regular Expression Complexity

BaseDraftLikelihood: High

Description

The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-492

CVEs mapped to this weakness (531)

page 21 of 27
  • CVE-2023-39174MedJul 25, 2023
    risk 0.28cvss 4.3epss 0.02

    In JetBrains TeamCity before 2023.05.2 a ReDoS attack was possible via integration with issue trackers

  • CVE-2023-36617MedJun 29, 2023
    risk 0.28cvss 5.3epss 0.02

    A ReDoS issue was discovered in the URI component before 0.12.2 for Ruby. The URI parser mishandles invalid URLs that have specific characters. There is an increase in execution time for parsing strings to URI objects with rfc2396_parser.rb and rfc3986_parser.rb. NOTE: this…

  • CVE-2023-26115MedJun 22, 2023
    risk 0.28cvss 5.3epss 0.02

    All versions of the package word-wrap are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of an insecure regular expression within the result variable.

  • CVE-2022-25883MedJun 21, 2023
    risk 0.28cvss 5.3epss 0.03

    Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.

  • CVE-2023-26103MedFeb 25, 2023
    risk 0.28cvss 5.3epss 0.01

    Versions of the package deno before 1.31.0 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the upgradeWebSocket function, which contains regexes in the form of /s*,s*/, used for splitting the Connection/Upgrade header. A specially crafted Connection/Upgrade…

  • CVE-2022-25881MedJan 31, 2023
    risk 0.28cvss 5.3epss 0.02

    This affects versions of the package http-cache-semantics before 4.1.1. The issue can be exploited via malicious request header values sent to a server, when that server reads the cache policy from the request using this library.

  • CVE-2022-25927MedJan 26, 2023
    risk 0.28cvss 5.3epss 0.02

    Versions of the package ua-parser-js from 0.7.30 and before 0.7.33, from 0.8.1 and before 1.0.33 are vulnerable to Regular Expression Denial of Service (ReDoS) via the trim() function.

  • CVE-2022-4131MedJan 12, 2023
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.8 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab instance by exploiting a regex…

  • CVE-2022-3514MedJan 12, 2023
    risk 0.28cvss 4.3epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 6.6 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. An attacker may cause Denial of Service on a GitLab instance by exploiting a regex…

  • CVE-2022-25918MedOct 27, 2022
    risk 0.28cvss 5.3epss 0.01

    The package shescape from 1.5.10 and before 1.6.1 are vulnerable to Regular Expression Denial of Service (ReDoS) via the escape function in index.js, due to the usage of insecure regex in the escapeArgBash function.

  • CVE-2022-2908MedOct 17, 2022
    risk 0.28cvss 4.3epss 0.01

    A potential DoS vulnerability was discovered in Gitlab CE/EE versions starting from 10.7 before 15.1.5, all versions starting from 15.2 before 15.2.3, all versions starting from 15.3 before 15.3.1 allowed an attacker to trigger high CPU usage via a special crafted input added in…

  • CVE-2022-24373MedSep 30, 2022
    risk 0.28cvss 5.3epss 0.01

    The package react-native-reanimated before 3.0.0-rc.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper usage of regular expression in the parser of Colors.js.

  • CVE-2022-21222MedSep 30, 2022
    risk 0.28cvss 5.3epss 0.02

    The package css-what before 2.1.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the usage of insecure regular expression in the re_attr variable of index.js. The exploitation of this vulnerability could be triggered via the parse function.

  • CVE-2022-25887MedAug 30, 2022
    risk 0.28cvss 5.3epss 0.01

    The package sanitize-html before 2.7.1 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure global regular expression replacement logic of HTML comment removal.

  • CVE-2022-25858MedJul 15, 2022
    risk 0.28cvss 5.3epss 0.03

    The package terser before 4.8.1, from 5.0.0 and before 5.14.2 are vulnerable to Regular Expression Denial of Service (ReDoS) due to insecure usage of regular expressions.

  • CVE-2022-25758MedJul 1, 2022
    risk 0.28cvss 5.3epss 0.02

    All versions of package scss-tokenizer are vulnerable to Regular Expression Denial of Service (ReDoS) via the loadAnnotation() function, due to the usage of insecure regex.

  • CVE-2022-1954MedJul 1, 2022
    risk 0.28cvss 4.3epss 0.01

    A Regular Expression Denial of Service vulnerability in GitLab CE/EE affecting all versions from 1.0.2 prior to 14.10.5, 15.0 prior to 15.0.4, and 15.1 prior to 15.1.1 allows an attacker to make a GitLab instance inaccessible via specially crafted web server response headers

  • CVE-2022-31110MedJun 29, 2022
    risk 0.28cvss 5.3epss 0.02

    RSSHub is an open source, extensible RSS feed generator. In commits prior to 5c4177441417 passing some special values to the `filter` and `filterout` parameters can cause an abnormally high CPU. This results in an impact on the performance of the servers and RSSHub services…

  • CVE-2022-21670MedJan 10, 2022
    risk 0.28cvss 5.3epss 0.02

    markdown-it is a Markdown parser. Prior to version 1.3.2, special patterns with length greater than 50 thousand characterss could slow down the parser significantly. Users should upgrade to version 12.3.2 to receive a patch. There are no known workarounds aside from upgrading.

  • CVE-2021-43843MedDec 20, 2021
    risk 0.28cvss 5.3epss 0.02

    jsx-slack is a package for building JSON objects for Slack block kit surfaces from JSX. The maintainers found the patch for CVE-2021-43838 in jsx-slack v4.5.1 is insufficient tfor protection from a Regular Expression Denial of Service (ReDoS) attack. If an attacker can put a lot…