VYPR

CWE-1333

Inefficient Regular Expression Complexity

BaseDraftLikelihood: High

Description

The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-492

CVEs mapped to this weakness (532)

page 6 of 27
  • CVE-2015-8858HigJan 23, 2017
    risk 0.49cvss 7.5epss 0.02

    The uglify-js package before 2.6.0 for Node.js allows attackers to cause a denial of service (CPU consumption) via crafted input in a parse call, aka a "regular expression denial of service (ReDoS)."

  • CVE-2015-8854HigJan 23, 2017
    risk 0.49cvss 7.5epss 0.04

    The marked package before 0.3.4 for Node.js allows attackers to cause a denial of service (CPU consumption) via unspecified vectors that trigger a "catastrophic backtracking issue for the em inline rule," aka a "regular expression denial of service (ReDoS)."

  • CVE-2015-8315HigJan 23, 2017
    risk 0.49cvss 7.5epss 0.07

    The ms package before 0.7.1 for Node.js allows attackers to cause a denial of service (CPU consumption) via a long version string, aka a "regular expression denial of service (ReDoS)."

  • CVE-2026-57577HigSep 14, 2026
    risk 0.46cvss —epss 0.00

    DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, a route containing multiple unconstrained parameters in one path segment can cause excessive regular-expression backtracking in DotvvmRoute.IsMatch when a remote…

  • CVE-2026-53500HigJul 31, 2026
    risk 0.46cvss 8.2epss 0.00

    Thumbor is an open-source photo thumbnail service by globo.com. Prior to 7.8.0, the ALLOWED_SOURCES configuration passes plain strings to re.match() without escaping dots, so a hostname differing at dot positions can match the allowlist. This issue is fixed in 7.8.0.

  • CVE-2025-45143HigJun 30, 2025
    risk 0.46cvss 7.0epss 0.00

    string-math v1.2.2 was discovered to contain a Regex Denial of Service (ReDoS) which is exploited via a crafted input.

  • CVE-2026-12061higJul 31, 2026
    risk 0.45cvss —epss —

    ### Summary `ReviewsCorpusReader` extracts feature annotations of the form *label* followed by a bracketed signed digit (e.g. a label then `[+2]`) from each review line, using the module-level `FEATURES` regex. The feature-label sub-pattern is unbounded — an optional greedy…

  • CVE-2025-54364MedAug 20, 2025
    risk 0.45cvss —epss 0.00

    Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. option_descriptions employs an inefficient regular expression pattern: "\s(:param)\s+(.+?)\s:(.*)" that is susceptible to catastrophic backtracking when processing…

  • CVE-2025-54363MedAug 20, 2025
    risk 0.45cvss —epss 0.00

    Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. extract_full_summary_from_signature employs an inefficient regular expression pattern: "\s(:param)\s+(.+?)\s:(.*)" that is susceptible to catastrophic backtracking when…

  • CVE-2024-8124HigSep 12, 2024
    risk 0.45cvss 7.5epss 0.40

    An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.1.7, starting from 17.2 prior to 17.2.5, starting from 17.3 prior to 17.3.2 which could cause Denial of Service via sending a specific POST request.

  • CVE-2024-2651MedMay 14, 2024
    risk 0.45cvss 6.5epss 0.33

    An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. It was possible for an attacker to cause a denial of service using maliciously crafted markdown…

  • CVE-2021-32837HigJan 17, 2023
    risk 0.44cvss 7.5epss 0.29

    mechanize, a library for automatically interacting with HTTP web servers, contains a regular expression that is vulnerable to regular expression denial of service (ReDoS) prior to version 0.4.6. If a web server responds in a malicious way, then mechanize could crash. Version…

  • CVE-2022-34402MedOct 10, 2022
    risk 0.44cvss 6.8epss 0.01

    Dell Wyse ThinOS 2205 contains a Regular Expression Denial of Service Vulnerability in UI. An admin privilege attacker could potentially exploit this vulnerability, leading to denial-of-service.

  • CVE-2024-52798HigDec 5, 2024
    risk 0.43cvss —epss 0.01

    path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. The regular expression that is vulnerable to backtracking can be generated in the 0.1.x release of…

  • CVE-2022-24713HigMar 8, 2022
    risk 0.43cvss 7.5epss 0.14

    regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide…

  • CVE-2026-63460HigSep 17, 2026
    risk 0.42cvss 7.5epss 0.00

    Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop GraphQL API allows an unauthenticated caller to supply a catastrophically backtracking pattern through StringOperators.regex. packages/core/src/service/helpers/list-query-builder/parse-filter-pa…

  • CVE-2026-92599HigSep 16, 2026
    risk 0.42cvss 7.5epss 0.00

    joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable to regular expression denial of service in the `Joi.string().isoDate()` validation rule. One of the regular expressions the rule applies to the input is unanchored, so a valid ISO…

  • CVE-2026-68497HigSep 11, 2026
    risk 0.42cvss 7.5epss 0.01

    jackson-databind binds a JSON string to a javax.xml.datatype.Duration or javax.xml.datatype.XMLGregorianCalendar field by passing the raw string verbatim to DatatypeFactory.newDuration(value) or newXMLGregorianCalendar(value) in CoreXMLDeserializers.Std._deserialize. These…

  • CVE-2026-75880MedSep 10, 2026
    risk 0.42cvss 6.5epss 0.00

    An authenticated client could attach a consumer with a selector containing crafted wildcard usage that results in excessive evaluation during message delivery attempts, occupying a shared broker thread and leading to denial of service. This issue affects Apache Artemis: from…

  • CVE-2026-87819HigSep 9, 2026
    risk 0.42cvss 7.5epss 0.00

    GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit author and committer fields. Attackers can craft a commit object with a malformed author field containing an unterminated angle bracket to cause…