VYPR

CWE-1333

Inefficient Regular Expression Complexity

BaseDraftLikelihood: High

Description

The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-492

CVEs mapped to this weakness (532)

page 5 of 27
  • CVE-2022-42124HigNov 15, 2022
    risk 0.49cvss 7.5epss 0.01

    ReDoS vulnerability in LayoutPageTemplateEntryUpgradeProcess in Liferay Portal 7.3.2 through 7.4.3.4 and Liferay DXP 7.2 fix pack 9 through fix pack 18, 7.3 before update 4, and DXP 7.4 GA allows remote attackers to consume an excessive amount of server resources via a crafted…

  • CVE-2022-37620HigOct 31, 2022
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDoS) flaw was found in kangax html-minifier 4.0.0 because of the reCustomIgnore regular expression.

  • CVE-2022-37259HigSep 20, 2022
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the string variable in babel.js.

  • CVE-2022-37260HigSep 15, 2022
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the input variable in main.js.

  • CVE-2022-37262HigSep 15, 2022
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDoS) flaw was found in stealjs steal 2.2.4 via the source and sourceWithComments variable in main.js.

  • CVE-2022-29158HigSep 2, 2022
    risk 0.49cvss 7.5epss 0.02

    Apache OFBiz up to version 18.12.05 is vulnerable to Regular Expression Denial of Service (ReDoS) in the way it handles URLs provided by external, unauthenticated users. Upgrade to 18.12.06 or apply patches at https://issues.apache.org/jira/browse/OFBIZ-12599

  • CVE-2022-36034HigAug 29, 2022
    risk 0.49cvss 7.5epss 0.01

    nitrado.js is a type safe wrapper for the Nitrado API. Possible ReDoS with lib input of `{{` and with many repetitions of `{{|`. This issue has been patched in all versions above `0.2.5`. There are currently no known workarounds.

  • CVE-2021-40901HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in scniro-validator v1.0.1 when validating crafted invalid emails.

  • CVE-2021-40900HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in regexfn v1.0.5 when validating crafted invalid emails.

  • CVE-2021-40899HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in repo-git-downloader v0.1.1 when downloading crafted invalid git repositories.

  • CVE-2021-40898HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in scaffold-helper v1.2.0 when copying crafted invalid files.

  • CVE-2021-40897HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in split-html-to-chars v1.0.5 when splitting crafted invalid htmls.

  • CVE-2021-40896HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in that-value v0.1.3 when validating crafted invalid emails.

  • CVE-2021-40895HigJun 27, 2022
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in todo-regex v0.1.1 when matching crafted invalid TODO statements.

  • CVE-2021-40894HigJun 24, 2022
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in underscore-99xp v1.7.2 when the deepValueSearch function is called.

  • CVE-2021-40893HigJun 24, 2022
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in validate-data v0.1.1 when validating crafted invalid emails.

  • CVE-2021-40892HigJun 24, 2022
    risk 0.49cvss 7.5epss 0.01

    A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in validate-color v2.1.0 when handling crafted invalid rgb(a) strings.

  • CVE-2022-26650HigMay 17, 2022
    risk 0.49cvss 7.5epss 0.03

    In Apache ShenYui, ShenYu-Bootstrap, RegexPredicateJudge.java uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where both parameters are controllable by the user. This can cause an attacker pass in malicious regular expressions and characters…

  • CVE-2022-25598HigMar 30, 2022
    risk 0.49cvss 7.5epss 0.02

    Apache DolphinScheduler user registration is vulnerable to Regular express Denial of Service (ReDoS) attacks, Apache DolphinScheduler users should upgrade to version 2.0.5 or higher.

  • CVE-2019-0820HigMay 16, 2019
    risk 0.49cvss 7.5epss 0.06

    A denial of service vulnerability exists when .NET Framework and .NET Core improperly process RegEx strings, aka '.NET Framework and .NET Core Denial of Service Vulnerability'. This CVE ID is unique from CVE-2019-0980, CVE-2019-0981.