VYPR

CWE-1333

Inefficient Regular Expression Complexity

BaseDraftLikelihood: High

Description

The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-492

CVEs mapped to this weakness (497)

page 25 of 25
  • CVE-2023-45806MedNov 10, 2023
    risk 0.00cvss 4.3epss 0.01

    Discourse is an open source platform for community discussion. Prior to version 3.1.3 of the `stable` branch and version 3.2.0.beta3 of the `beta` and `tests-passed` branches, if a user has been quoted and uses a `|` in their full name, they might be able to trigger a bug that…

  • CVE-2023-30858MedApr 28, 2023
    risk 0.00cvss 5.3epss 0.01

    The Denosaurs emoji package provides emojis for dinosaurs. Starting in version 0.1.0 and prior to version 0.3.0, the reTrimSpace regex has 2nd degree polynomial inefficiency, leading to a delayed response given a big payload. The issue has been patched in 0.3.0. As a workaround,…

  • CVE-2021-32848HigFeb 20, 2023
    risk 0.00cvss 7.5epss 0.01

    Octobox is software for managing GitHub notifications. Prior to pull request (PR) 2807, a user of the system can provide a specifically crafted search query string that will trigger a ReDoS vulnerability. This issue is fixed in PR 2807.

  • CVE-2020-36661LowFeb 12, 2023
    risk 0.00cvss 3.5epss 0.01

    A vulnerability was found in Kong lua-multipart 0.5.8-1. It has been declared as problematic. This vulnerability affects the function is_header of the file src/multipart.lua. The manipulation leads to inefficient regular expression complexity. Upgrading to version 0.5.9-1 is…

  • CVE-2023-25167MedFeb 8, 2023
    risk 0.00cvss 6.5epss 0.01

    Discourse is an open source discussion platform. In affected versions a malicious user can cause a regular expression denial of service using a carefully crafted git URL. This issue is patched in the latest stable, beta and tests-passed versions of Discourse. Users are advised…

  • CVE-2023-23621HigJan 28, 2023
    risk 0.00cvss 8.6epss 0.01

    Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and version 3.1.0.beta2 on the `beta` and `tests-passed` branches, a malicious user can cause a regular expression denial of service using a carefully crafted user agent. This issue is…

  • CVE-2022-23548MedJan 5, 2023
    risk 0.00cvss 6.5epss 0.01

    Discourse is an option source discussion platform. Prior to version 2.8.14 on the `stable` branch and version 2.9.0.beta16 on the `beta` and `tests-passed` branches, parsing posts can be susceptible to regular expression denial of service (ReDoS) attacks. This issue is patched…

  • CVE-2022-36064MedSep 6, 2022
    risk 0.00cvss 5.9epss 0.01

    Shescape is a shell escape package for JavaScript. An Inefficient Regular Expression Complexity vulnerability impacts users that use Shescape to escape arguments for the Unix shells `Bash` and `Dash`, or any not-officially-supported Unix shell; and/or using the `escape` or…

  • CVE-2022-29169HigJun 1, 2022
    risk 0.00cvss 7.5epss 0.01

    BigBlueButton is an open source web conferencing system. Versions starting with 2.2 and prior to 2.3.19, 2.4.7, and 2.5.0-beta.2 are vulnerable to regular expression denial of service (ReDoS) attacks. By using specific a RegularExpression, an attacker can cause denial of service…

  • CVE-2021-45470HigDec 23, 2021
    risk 0.00cvss 7.5epss 0.02

    lib/DatabaseLayer.py in cve-search before 4.1.0 allows regular expression injection, which can lead to ReDoS (regular expression denial of service) or other impacts.

  • CVE-2021-41115MedOct 7, 2021
    risk 0.00cvss 4.3epss 0.02

    Zulip is an open source team chat server. In affected versions Zulip allows organization administrators on a server to configure "linkifiers" that automatically create links from messages that users send, detected via arbitrary regular expressions. Malicious organization…

  • CVE-2021-23446HigSep 29, 2021
    risk 0.00cvss 7.5epss 0.03

    The package handsontable before 10.0.0; the package handsontable from 0 and before 10.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) in Handsontable.helper.isNumeric function.

  • CVE-2021-3649HigJul 16, 2021
    risk 0.00cvss 7.5epss 0.01

    chatwoot is vulnerable to Inefficient Regular Expression Complexity

  • CVE-2017-18077HigJan 27, 2018
    risk 0.00cvss 7.5epss 0.03

    index.js in brace-expansion before 1.1.7 is vulnerable to Regular Expression Denial of Service (ReDoS) attacks, as demonstrated by an expand argument containing many comma characters.

  • CVE-2015-5145Jul 14, 2015
    risk 0.00cvss epss 0.03

    validators.URLValidator in Django 1.8.x before 1.8.3 allows remote attackers to cause a denial of service (CPU consumption) via unspecified vectors.

  • CVE-2009-3695Oct 13, 2009
    risk 0.00cvss epss 0.04

    Algorithmic complexity vulnerability in the forms library in Django 1.0 before 1.0.4 and 1.1 before 1.1.1 allows remote attackers to cause a denial of service (CPU consumption) via a crafted (1) EmailField (email address) or (2) URLField (URL) that triggers a large amount of…

  • CVE-2009-1190Apr 27, 2009
    risk 0.00cvss epss 0.03

    Algorithmic complexity vulnerability in the java.util.regex.Pattern.compile method in Sun Java Development Kit (JDK) before 1.6, when used with spring.jar in SpringSource Spring Framework 1.1.0 through 2.5.6 and 3.0.0.M1 through 3.0.0.M2 and dm Server 1.0.0 through 1.0.2, allows…