VYPR

CWE-1333

Inefficient Regular Expression Complexity

BaseDraftLikelihood: High

Description

The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

Hierarchy (View 1000)

Parents

Children

none

Related attack patterns (CAPEC)

CAPEC-492

CVEs mapped to this weakness (532)

page 7 of 27
  • CVE-2026-80205HigAug 26, 2026
    risk 0.42cvss 7.5epss 0.00

    NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.findall() and TokenSearcher.findall() methods that accept user-supplied regular expressions without validation or timeout. Attackers can supply crafted regex patterns that cause…

  • CVE-2026-79770HigAug 25, 2026
    risk 0.42cvss 7.5epss 0.00

    Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokenizer affecting string-literal and identifier tokenization. Attackers can inject adversarial CSS selectors into methods like Node#css, Node#at_css, and…

  • CVE-2026-72818HigAug 20, 2026
    risk 0.42cvss 7.5epss 0.01

    The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize, contains a naked-domain branch whose domain-label prefix [a-z0-9]+(?:[.\-][a-z0-9]+)* is unbounded. Input consisting of many alternating label…

  • CVE-2026-62317HigAug 19, 2026
    risk 0.42cvss 7.5epss 0.01

    Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's email subaddressing blocklist in packages/core/src/libraries/sign-in-experience/email-blocklist-policy.ts used the attacker-controlled domain from email input to construct…

  • CVE-2026-59893HigAug 17, 2026
    risk 0.42cvss 7.5epss 0.00

    sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/keywords.py and the per-position loop in sqlparse/lexer.py repeatedly scan unmatched dollar-quoted literal and multiline-comment delimiters, causing quadratic CPU consumption through…

  • CVE-2026-58436HigAug 13, 2026
    risk 0.42cvss 7.5epss 0.00

    ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests

  • CVE-2026-67991HigAug 13, 2026
    risk 0.42cvss 7.5epss 0.00

    crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition in RubyLLM::Utils.underscore on Ruby 3.1.x. A very long crafted class, agent, or tool name can cause excessive CPU consumption and a denial…

  • CVE-2026-67422HigAug 6, 2026
    risk 0.42cvss 7.5epss 0.01

    pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline processors (caret, tilde, betterem, and magiclink) use regular expressions whose content groups can partition a run of delimiter characters in…

  • CVE-2026-68749HigAug 6, 2026
    risk 0.42cvss 7.5epss 0.00

    Inefficient Regular Expression Complexity vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthenticated remote attacker to exhaust server CPU via a long CSS declaration in sanitized HTML. The declaration regex in HtmlSanitizeEx.Scrubber.CSS.scrub/1…

  • CVE-2026-23985MedJul 30, 2026
    risk 0.42cvss 6.5epss 0.00

    A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through 5.0.0. The vulnerability is located in the sql_parse.py component, specifically within the SQL_REGEX used for parsing SQL statements in the sqlparse library integration.…

  • CVE-2026-60075HigJul 30, 2026
    risk 0.42cvss 7.5epss 0.00

    Date::Manip versions through 7.00 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in _parse_time. _parse_time removes a time from anywhere in the string with the unanchored substitution `s/$timerx/ /`, where $timerx is an…

  • CVE-2026-52746HigJul 17, 2026
    risk 0.42cvss 7.5epss 0.01

    JSONata is a JSON query and transformation language. Prior to 2.2.0 and 1.8.9, malicious non-matching inputs to the $toMillis function can cause superlinear backtracking in the ISO-8601 validation regex, leading to denial of service in applications that evaluate user-provided…

  • CVE-2026-14741HigJul 17, 2026
    risk 0.42cvss 7.5epss 0.00

    HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date. parse_date() matches the date string against a chain of alternative regexes, and str2time() delegates to it. Several of these patterns place unbounded quantifiers next…

  • CVE-2026-45367HigJul 16, 2026
    risk 0.42cvss 7.5epss 0.01

    HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.7, the FHIRPathEngine implementation passes user-controlled regular expressions from matches(), matchesFull(), and replaceMatches() to Java regex operations…

  • CVE-2026-49477HigJul 14, 2026
    risk 0.42cvss 7.5epss 0.01

    Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to catastrophic backtracking when processing an attribute selector with an unterminated quoted value in…

  • CVE-2026-48801HigJul 14, 2026
    risk 0.42cvss 7.5epss 0.00

    linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package's primary public API, has O(N²) algorithmic complexity for inputs containing many fuzzy links or emails because the JavaScript-level scan loop re-slices…

  • CVE-2026-45305HigJul 14, 2026
    risk 0.42cvss 7.5epss 0.01

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser::cleanup() used regular expressions with overlapping quantifiers for YAML directive, comment, and document…

  • CVE-2026-45133HigJul 14, 2026
    risk 0.42cvss 7.5epss 0.01

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, when the parser is exposed to attacker-controlled input, deeply nested mappings or sequences cause both the block-level…

  • CVE-2026-45756HigJul 14, 2026
    risk 0.42cvss 7.5epss 0.01

    Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.3.0-BETA1 until 7.4.12 and 8.0.12, the JsonPath component compiles attacker-controlled match() and search() filter patterns directly into preg_match() without a length cap,…

  • CVE-2026-55470HigJul 8, 2026
    risk 0.42cvss 7.5epss 0.01

    HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, the fix for CVE-2026-45367 incompletely patched the DSTU2 module, leaving FHIRPathEngine.matches() in org.hl7.fhir.dstu2/utils/FHIRPathEngine.java to call…