CWE-1333
High likelihoodInefficient Regular Expression Complexity
The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.
457 vulnerabilities with CWE-1333
CVE-2026-23985
MEDIUM
Apache Superset: Regular Expression Denial of Service (ReDoS) in SQL Parser
CVE-2026-60075
Perl Date::Manip <= 6.99 _parse_time - CPU Exhaustion
CVE-2026-16270
MEDIUM
ReDoS in Open Mercato
CVE-2026-49485
HIGH
HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
CVSS 7.5
CVE-2026-52746
HIGH
JSONata: Malicious inputs to "$toMillis" function can cause resource exhaustion
CVSS 7.5
CVE-2026-14741
HIGH
HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date
CVSS 7.5
CVE-2026-62237
MEDIUM
Grav < 2.0.4 ReDoS via regex_replace in Sandbox
CVSS 6.5
CVE-2026-45367
HIGH
HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
CVSS 7.5
CVE-2026-49477
HIGH
Soup Sieve: Regular Expression Denial of Service (ReDoS) in soupsieve Selector Parser
CVSS 7.5
CVE-2026-48801
HIGH
linkify-it: Quadratic algorithmic complexity in LinkifyIt#match scan loop
CVE-2026-48125
MEDIUM
UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()`
CVSS 5.3
CVE-2026-45305
HIGH
Symfony: YAML Parser ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex
CVSS 7.5
CVE-2026-45133
HIGH
Symfony: [Yaml] Harden the parser when handling untrusted input
CVSS 7.5
CVE-2026-45756
HIGH
Symfony: JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
CVSS 7.5
CVE-2026-6850
MEDIUM
Crafted message attachment causes client-side denial of service via markdown parser regex backtracking in Mattermost
CVSS 6.5
CVE-2026-57584
HIGH
Phalcon Router < 5.15.0 - Regular Expression Denial of Service
CVE-2026-59220
MEDIUM
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
CVSS 6.5
CVE-2026-55470
HIGH
HAPI FHIR: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS
CVSS 7.5
CVE-2026-15154
MEDIUM
Guardrails-detectors: guardrails-detectors: unauthenticated regular-expression denial of service (redos) via detector_params.regex
CVSS 6.5
CVE-2026-59928
HIGH
Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
CVSS 7.5
CVE-2026-59925
HIGH
inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
CVSS 7.5
CVE-2026-59922
HIGH
Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
CVSS 7.5
CVE-2026-14895
HIGH
String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service
CVSS 7.5
CVE-2026-55574
HIGH
vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends
CVSS 7.5
CVE-2026-58578
MEDIUM
LobeChat < 2.2.10-canary.15 - Regular Expression Denial of Service in GitHub Skill Import
CVSS 6.5
Details
Vulnerabilities
457
Exploit Likelihood
High