VYPR

CWE-1333

Inefficient Regular Expression Complexity

BaseDraftLikelihood: High

Description

The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-492

CVEs mapped to this weakness (497)

page 23 of 25
  • CVE-2018-25061MedDec 31, 2022
    risk 0.21cvss 4.3epss 0.01

    A vulnerability was found in rgb2hex up to 0.1.5. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to inefficient regular expression complexity. The attack may be initiated remotely. Upgrading to version 0.1.6 is able to…

  • CVE-2026-35041MedApr 9, 2026
    risk 0.20cvss 4.2epss 0.00

    fast-jwt provides fast JSON Web Token (JWT) implementation. From 5.0.0 to 6.2.0, a denial-of-service condition exists in fast-jwt when the allowedAud verification option is configured using a regular expression. Because the aud claim is attacker-controlled and the library…

  • CVE-2024-6434LowJul 4, 2024
    risk 0.20cvss 3.1epss 0.01

    The Premium Addons for Elementor plugin for WordPress is vulnerable to Regular Expression Denial of Service (ReDoS) in all versions up to, and including, 4.10.35. This is due to processing user-supplied input as a regular expression. This makes it possible for authenticated…

  • CVE-2025-27220MedMar 4, 2025
    risk 0.19cvss 4.0epss 0.01

    In the CGI gem before 0.4.2 for Ruby, a Regular Expression Denial of Service (ReDoS) vulnerability exists in the Util#escapeElement method.

  • CVE-2025-3985LowApr 27, 2025
    risk 0.18cvss 2.7epss 0.01

    A vulnerability was found in Apereo CAS 5.2.6. It has been classified as problematic. This affects the function ResponseEntity of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mgmt\services\web\ManageRegisteredServicesMultiActionControl…

  • CVE-2026-41848LowJun 9, 2026
    risk 0.17cvss 3.7epss 0.00

    Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(String pattern, String path),…

  • CVE-2025-4727LowMay 15, 2025
    risk 0.17cvss 3.7epss 0.01

    A vulnerability was found in Meteor up to 3.2.1 and classified as problematic. This issue affects the function Object.assign of the file packages/ddp-server/livedata_server.js. The manipulation of the argument forwardedFor leads to inefficient regular expression complexity. The…

  • CVE-2023-26112LowApr 3, 2023
    risk 0.17cvss 3.7epss 0.01

    All versions of the package configobj are vulnerable to Regular Expression Denial of Service (ReDoS) via the validate function, using (.+?)\((.*)\). **Note:** This is only exploitable in the case of a developer, putting the offending value in a server side configuration file.

  • CVE-2022-42965LowNov 9, 2022
    risk 0.17cvss 3.7epss 0.01

    An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the snowflake-connector-python PyPI package, when an attacker is able to supply arbitrary input to the undocumented get_file_transfer_type method

  • CVE-2021-4437LowFeb 12, 2024
    risk 0.16cvss 3.5epss 0.00

    A vulnerability, which was classified as problematic, has been found in dbartholomae lambda-middleware frameguard up to 1.0.4. Affected by this issue is some unknown functionality of the file packages/json-deserializer/src/JsonDeserializer.ts of the component JSON Mime-Type…

  • CVE-2018-25077LowJan 18, 2023
    risk 0.16cvss 3.5epss 0.01

    A vulnerability was found in melnaron mel-spintax. It has been rated as problematic. Affected by this issue is some unknown functionality of the file lib/spintax.js. The manipulation of the argument text leads to inefficient regular expression complexity. The name of the patch…

  • CVE-2022-4891LowJan 17, 2023
    risk 0.16cvss 3.5epss 0.01

    A vulnerability has been found in Sisimai up to 4.25.14p11 and classified as problematic. This vulnerability affects the function to_plain of the file lib/sisimai/string.rb. The manipulation leads to inefficient regular expression complexity. The exploit has been disclosed to…

  • CVE-2020-36649LowJan 11, 2023
    risk 0.16cvss 3.5epss 0.01

    A vulnerability was found in mholt PapaParse up to 5.1.x. It has been classified as problematic. Affected is an unknown function of the file papaparse.js. The manipulation leads to inefficient regular expression complexity. Upgrading to version 5.2.0 is able to address this…

  • CVE-2018-25074LowJan 11, 2023
    risk 0.16cvss 3.5epss 0.01

    A vulnerability was found in Prestaul skeemas and classified as problematic. This issue affects some unknown processing of the file validators/base.js. The manipulation of the argument uri leads to inefficient regular expression complexity. The patch is named…

  • CVE-2017-20165LowJan 9, 2023
    risk 0.16cvss 3.5epss 0.02

    A vulnerability classified as problematic has been found in debug-js debug up to 3.0.x. This affects the function useColors of the file src/node.js. The manipulation of the argument str leads to inefficient regular expression complexity. Upgrading to version 3.1.0 is able to…

  • CVE-2021-4306LowJan 7, 2023
    risk 0.16cvss 3.5epss 0.01

    A vulnerability classified as problematic has been found in cronvel terminal-kit up to 2.1.7. Affected is an unknown function. The manipulation leads to inefficient regular expression complexity. Upgrading to version 2.1.8 is able to address this issue. The name of the patch is…

  • CVE-2021-4305LowJan 5, 2023
    risk 0.16cvss 3.5epss 0.01

    A vulnerability was found in Woorank robots-txt-guard. It has been rated as problematic. Affected by this issue is the function makePathPattern of the file lib/patterns.js. The manipulation of the argument pattern leads to inefficient regular expression complexity. The exploit…

  • CVE-2015-10005LowDec 27, 2022
    risk 0.16cvss 3.5epss 0.01

    A vulnerability was found in markdown-it up to 2.x. It has been classified as problematic. Affected is an unknown function of the file lib/common/html_re.js. The manipulation leads to inefficient regular expression complexity. Upgrading to version 3.0.0 is able to address this…

  • CVE-2026-4539LowMar 22, 2026
    risk 0.14cvss 3.3epss 0.00

    A security flaw has been discovered in pygments up to 2.19.2. The impacted element is the function AdlLexer of the file pygments/lexers/archetype.py. The manipulation results in inefficient regular expression complexity. The attack is only possible with local access. The exploit…

  • CVE-2026-3293LowFeb 27, 2026
    risk 0.14cvss 3.3epss 0.00

    A weakness has been identified in snowflakedb snowflake-jdbc up to 4.0.1. Impacted is the function SdkProxyRoutePlanner of the file src/main/java/net/snowflake/client/internal/core/SdkProxyRoutePlanner.java of the component JDBC URL Handler. Executing a manipulation of the…