VYPR

CWE-1333

Inefficient Regular Expression Complexity

BaseDraftLikelihood: High

Description

The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-492

CVEs mapped to this weakness (532)

page 3 of 27
  • CVE-2024-8764HigMar 20, 2025
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in lunary-ai/lunary, as of commit be54057, allows users to upload and execute arbitrary regular expressions on the server side. This can lead to a Denial of Service (DoS) condition, as certain regular expressions can cause excessive resource consumption, blocking…

  • CVE-2024-8763HigMar 20, 2025
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDoS) vulnerability exists in the lunary-ai/lunary repository, specifically in the compileTextTemplate function. The affected version is git be54057. An attacker can exploit this vulnerability by manipulating the regular expression…

  • CVE-2024-7779HigMar 20, 2025
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in danswer-ai/danswer version 1 allows an attacker to perform a Regular Expression Denial of Service (ReDoS) by manipulating regular expressions. This can significantly slow down the application's response time and potentially render it completely unusable.

  • CVE-2024-10624HigMar 20, 2025
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDoS) vulnerability exists in the gradio-app/gradio repository, affecting the gr.Datetime component. The affected version is git commit 98cbcae. The vulnerability arises from the use of a regular expression…

  • CVE-2024-10550HigMar 20, 2025
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the `/3/ParseSetup` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. The endpoint applies a user-specified regular expression to a user-controllable string. This can be exploited by an attacker to cause inefficient regular…

  • CVE-2024-10549HigMar 20, 2025
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in the `/3/Parse` endpoint of h2oai/h2o-3 version 3.46.0.1 allows for a denial of service (DoS) attack. The endpoint uses a user-specified string to construct a regular expression, which is then applied to another user-specified string. By sending multiple…

  • CVE-2024-46242HigJan 7, 2025
    risk 0.49cvss 7.5epss 0.01

    An issue in the validate_email function in CTFd/utils/validators/__init__.py of CTFd 3.7.3 allows attackers to cause a Regular expression Denial of Service (ReDoS) via supplying a crafted string as e-mail address during registration.

  • CVE-2024-41766HigJan 4, 2025
    risk 0.49cvss 7.5epss 0.00

    IBM Engineering Lifecycle Optimization - Publishing 7.0.2 and 7.0.3 could allow a remote attacker to cause a denial of service using a complex regular expression.

  • CVE-2020-26308HigOct 26, 2024
    risk 0.49cvss 7.5epss 0.01

    Validate.js provides a declarative way of validating javascript objects. Versions 0.13.1 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available.

  • CVE-2020-26305HigOct 26, 2024
    risk 0.49cvss 7.5epss 0.00

    CommonRegexJS is a CommonRegex port for JavaScript. All available versions contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available.

  • CVE-2020-26304HigOct 26, 2024
    risk 0.49cvss 7.5epss 0.01

    Foundation is a front-end framework. Versions 6.3.3 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, it is unknown if any fixes are available.

  • CVE-2020-26303HigOct 26, 2024
    risk 0.49cvss 7.5epss 0.01

    insane is a whitelist-oriented HTML sanitizer. Versions 2.6.2 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available.

  • CVE-2024-48938HigOct 11, 2024
    risk 0.49cvss 7.5epss 0.01

    Znuny before LTS 6.5.1 through 6.5.10 and 7.0.1 through 7.0.16 allows DoS/ReDos via email. Parsing the content of emails where HTML code is copied from Microsoft Word could lead to high CPU usage and block the parsing process.

  • CVE-2024-25885HigOct 8, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in the getcolor function in utils.py of xhtml2pdf v0.2.13 allows attackers to cause a Regular expression Denial of Service (ReDOS) via supplying a crafted string.

  • CVE-2024-39249HigJul 1, 2024
    risk 0.49cvss 7.5epss 0.01

    Async <= 2.6.4 and <= 3.2.5 are vulnerable to ReDoS (Regular Expression Denial of Service) while parsing function in autoinject function. NOTE: this is disputed by the supplier because there is no realistic threat model: regular expressions are not used with untrusted input.

  • CVE-2024-5552HigJun 6, 2024
    risk 0.49cvss 7.5epss 0.01

    kubeflow/kubeflow is vulnerable to a Regular Expression Denial of Service (ReDoS) attack due to inefficient regular expression complexity in its email validation mechanism. An attacker can remotely exploit this vulnerability without authentication by providing specially crafted…

  • CVE-2024-4148HigJun 1, 2024
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDoS) vulnerability exists in the lunary-ai/lunary application, version 1.2.10. An attacker can exploit this vulnerability by maliciously manipulating regular expressions, which can significantly impact the response time of the…

  • CVE-2024-28716HigApr 30, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in OpenStack Storlets yoga-eom allows a remote attacker to execute arbitrary code via the gateway.py component.

  • CVE-2024-4056HigApr 26, 2024
    risk 0.49cvss 7.5epss 0.01

    Denial of service condition in M-Files Server in versions before 24.4.13592.4 and after 23.11 (excluding 24.2 LTS) allows unauthenticated user to consume computing resources.

  • CVE-2024-22363HigApr 5, 2024
    risk 0.49cvss 7.5epss 0.01

    SheetJS Community Edition before 0.20.2 is vulnerable.to Regular Expression Denial of Service (ReDoS).