CWE-1333

High likelihood

Inefficient Regular Expression Complexity

Parent: CWE-407 - Inefficient Algorithmic Complexity

The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

457 vulnerabilities with CWE-1333
CVE-2026-23985 MEDIUM
Apache Superset: Regular Expression Denial of Service (ReDoS) in SQL Parser
CVE-2026-60075
Perl Date::Manip <= 6.99 _parse_time - CPU Exhaustion
CVE-2026-16270 MEDIUM
ReDoS in Open Mercato
CVE-2026-49485 HIGH
HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
CVSS 7.5
CVE-2026-52746 HIGH
JSONata: Malicious inputs to "$toMillis" function can cause resource exhaustion
CVSS 7.5
CVE-2026-14741 HIGH
HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date
CVSS 7.5
CVE-2026-62237 MEDIUM
Grav < 2.0.4 ReDoS via regex_replace in Sandbox
CVSS 6.5
CVE-2026-45367 HIGH
HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
CVSS 7.5
CVE-2026-49477 HIGH
Soup Sieve: Regular Expression Denial of Service (ReDoS) in soupsieve Selector Parser
CVSS 7.5
CVE-2026-48801 HIGH
linkify-it: Quadratic algorithmic complexity in LinkifyIt#match scan loop
CVE-2026-48125 MEDIUM
UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()`
CVSS 5.3
CVE-2026-45305 HIGH
Symfony: YAML Parser ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex
CVSS 7.5
CVE-2026-45133 HIGH
Symfony: [Yaml] Harden the parser when handling untrusted input
CVSS 7.5
CVE-2026-45756 HIGH
Symfony: JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
CVSS 7.5
CVE-2026-6850 MEDIUM
Crafted message attachment causes client-side denial of service via markdown parser regex backtracking in Mattermost
CVSS 6.5
CVE-2026-57584 HIGH
Phalcon Router < 5.15.0 - Regular Expression Denial of Service
CVE-2026-59220 MEDIUM
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
CVSS 6.5
CVE-2026-55470 HIGH
HAPI FHIR: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS
CVSS 7.5
CVE-2026-15154 MEDIUM
Guardrails-detectors: guardrails-detectors: unauthenticated regular-expression denial of service (redos) via detector_params.regex
CVSS 6.5
CVE-2026-59928 HIGH
Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
CVSS 7.5
CVE-2026-59925 HIGH
inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
CVSS 7.5
CVE-2026-59922 HIGH
Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
CVSS 7.5
CVE-2026-14895 HIGH
String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service
CVSS 7.5
CVE-2026-55574 HIGH
vLLM: ReDoS via structured_outputs.regex compiled without timeout in xgrammar and outlines backends
CVSS 7.5
CVE-2026-58578 MEDIUM
LobeChat < 2.2.10-canary.15 - Regular Expression Denial of Service in GitHub Skill Import
CVSS 6.5
Details
Vulnerabilities 457
Exploit Likelihood High