CWE-1333

High likelihood

Inefficient Regular Expression Complexity

Parent: CWE-407 - Inefficient Algorithmic Complexity

The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.

410 vulnerabilities with CWE-1333
CVE-2021-39933 MEDIUM
Gitlab < 14.3.6 - Denial of Service
CVSS 4.3
CVE-2021-43805 HIGH
Solidus <3.1.4, <3.0.4, <2.11.13 - DoS
CVSS 7.5
CVE-2021-3765 HIGH
validator.js - Inefficient Regular Expression Complexity
CVSS 7.5
CVE-2021-41115 MEDIUM
Zulip - DoS
CVSS 4.3
CVE-2021-23446 HIGH
Handsontable < 10.0.0 - Denial of Service
CVSS 7.5
CVE-2021-3828 HIGH
nltk - Inefficient Regular Expression Complexity
CVSS 7.5
CVE-2021-3822 HIGH
jsoneditor - Buffer Overflow
CVSS 7.5
CVE-2021-3820 HIGH
inflect - Code Injection
CVSS 7.5
CVE-2021-3810 HIGH
code-server - Code Injection
CVSS 7.5
CVE-2021-3807 HIGH
ansi-regex - Inefficient Regular Expression Complexity
CVSS 7.5
CVE-2021-3804 HIGH
taro - Code Injection
CVSS 7.5
CVE-2021-3803 HIGH
nth-check - Inefficient Regular Expression Complexity
CVSS 7.5
CVE-2021-3795 HIGH
semver-regex - Inefficient Regular Expression Complexity
CVSS 7.5
CVE-2021-3801 MEDIUM
prism - Buffer Overflow
CVSS 6.5
CVE-2021-3794 HIGH
vuelidate - Inefficient Regular Expression Complexity
CVSS 7.5
CVE-2021-3777 HIGH
nodejs-tmpl - Inefficient Regular Expression Complexity
CVSS 7.5
CVE-2021-3749 HIGH
axios - RCE
CVSS 7.5
CVE-2021-3649 HIGH
chatwoot - Code Injection
CVSS 7.5
CVE-2021-33502 HIGH
normalize-url <4.5.1, <5.3.1, <6.0.1 - DoS
CVSS 7.5
CVE-2021-23364 MEDIUM
Browserslist < 4.16.5 - Denial of Service
CVSS 5.3
CVE-2021-23382 MEDIUM
Postcss < 7.0.36 - Denial of Service
CVSS 5.3
CVE-2021-23362 MEDIUM
Npmjs Hosted-git-info < 2.8.9 - Denial of Service
CVSS 5.3
CVE-2021-25292 MEDIUM
Pillow <8.1.1 - ReDoS
CVSS 6.5
CVE-2021-27291 HIGH
pygments 1.1+ - DoS
CVSS 7.5
CVE-2021-28092 HIGH
is-svg <4.2.1 - DoS
CVSS 7.5
Details
Vulnerabilities 410
Exploit Likelihood High