VYPR

CWE-1333

Inefficient Regular Expression Complexity

BaseDraftLikelihood: High

Description

The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-492

CVEs mapped to this weakness (532)

page 4 of 27
  • CVE-2024-25354HigMar 27, 2024
    risk 0.49cvss 7.5epss 0.01

    RegEx Denial of Service in domain-suffix 1.0.8 allows attackers to crash the application via crafted input to the parse function.

  • CVE-2023-51931HigFeb 16, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in alanclarke URLite v.3.1.0 allows an attacker to cause a denial of service (DoS) via a crafted payload to the parsing function.

  • CVE-2024-21490HigFeb 10, 2024
    risk 0.49cvss 7.5epss 0.02

    This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. With large carefully-crafted input, this can…

  • CVE-2023-46402HigNov 18, 2023
    risk 0.49cvss 7.5epss 0.01

    git-urls 1.0.0 allows ReDOS (Regular Expression Denial of Service) in urls.go.

  • CVE-2023-39619HigOct 25, 2023
    risk 0.49cvss 7.5epss 0.01

    ReDos in NPMJS Node Email Check v.1.0.4 allows an attacker to cause a denial of service via a crafted string to the scpSyntax component.

  • CVE-2023-43646HigSep 27, 2023
    risk 0.49cvss 8.6epss 0.01

    get-func-name is a module to retrieve a function's name securely and consistently both in NodeJS and the browser. Versions prior to 2.0.1 are subject to a regular expression denial of service (redos) vulnerability which may lead to a denial of service when parsing malicious…

  • CVE-2023-39663HigAug 29, 2023
    risk 0.49cvss 7.5epss 0.01

    Mathjax up to v2.7.9 was discovered to contain two Regular expression Denial of Service (ReDoS) vulnerabilities in MathJax.js via the components pattern and markdownPattern. NOTE: the vendor disputes this because the regular expressions are not applied to user input; thus, there…

  • CVE-2023-40599HigAug 25, 2023
    risk 0.49cvss 7.5epss 0.01

    Regular expression Denial-of-Service (ReDoS) exists in multiple add-ons for Mailform Pro CGI 4.3.1.3 and earlier, which allows a remote unauthenticated attacker to cause a denial-of-service condition. Affected add-ons are as follows: call/call.js, prefcodeadv/search.cgi,…

  • CVE-2023-3994HigAug 2, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 9.3 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 before 16.2.2. A Regular Expression Denial of Service was possible via sending crafted payloads…

  • CVE-2023-3424HigJul 13, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 10.3 before 15.11.10, all versions starting from 16.0 before 16.0.6, all versions starting from 16.1 before 16.1.1. A Regular Expression Denial of Service was possible via sending crafted payloads…

  • CVE-2023-32610HigJun 29, 2023
    risk 0.49cvss 7.5epss 0.01

    Mailform Pro CGI 4.3.1.2 and earlier allows a remote unauthenticated attacker to cause a denial-of-service (DoS) condition.

  • CVE-2023-33289HigJun 21, 2023
    risk 0.49cvss 7.5epss 0.01

    The urlnorm crate through 0.1.4 for Rust allows Regular Expression Denial of Service (ReDos) via a crafted URL to lib.rs. NOTE: the Supplier disputes this, taking the position that "Slow printing of URLs is not a CVE."

  • CVE-2023-2199HigJun 7, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads…

  • CVE-2023-2198HigJun 7, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression Denial of Service was possible via sending crafted payloads…

  • CVE-2023-2132HigJun 6, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A DollarMathPostFilter Regular Expression Denial of Service in was possible by…

  • CVE-2020-6817HigFeb 16, 2023
    risk 0.49cvss 7.5epss 0.01

    bleach.clean behavior parsing style attributes could result in a regular expression denial of service (ReDoS). Calls to bleach.clean with an allowed tag with an allowed style attribute are vulnerable to ReDoS. For example, bleach.clean(..., attributes={'a': ['style']}).

  • CVE-2023-23925HigFeb 3, 2023
    risk 0.49cvss 8.6epss 0.01

    Switcher Client is a JavaScript SDK to work with Switcher API which is cloud-based Feature Flag. Unsanitized input flows into Strategy match operation (EXIST), where it is used to build a regular expression. This may result in a Regular expression Denial of Service attack…

  • CVE-2023-24038HigJan 21, 2023
    risk 0.49cvss 7.5epss 0.01

    The HTML-StripScripts module through 1.06 for Perl allows _hss_attval_style ReDoS because of catastrophic backtracking for HTML content with certain style attributes.

  • CVE-2020-26302HigDec 22, 2022
    risk 0.49cvss 7.5epss 0.01

    is.js is a general-purpose check library. Versions 0.9.0 and prior contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). is.js uses a regex copy-pasted from a gist to validate URLs. Trying to validate a malicious string can…

  • CVE-2022-30122HigDec 5, 2022
    risk 0.49cvss 7.5epss 0.02

    A possible denial of service vulnerability exists in Rack <2.0.9.1, <2.1.4.1 and <2.2.3.1 in the multipart parsing component of Rack.