CWE-407

Low likelihood

Inefficient Algorithmic Complexity

Parent: CWE-405 - Asymmetric Resource Consumption (Amplification)

An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

124 vulnerabilities with CWE-407
CVE-2026-67216 MEDIUM
cJSON cJSON_Compare Exponential Complexity Denial of Service
CVSS 5.9
CVE-2026-6879 LOW
Python Software Foundation CPython - Quadratic Behavior in xml.etree.ElementPath Index Predicates
CVE-2026-55685 HIGH
React Router: Unauthenticated Denial of Service via Inefficient Route Matching
CVE-2026-64644 MEDIUM
Next.js: Denial of Service in the Image Optimization API using SVGs
CVSS 5.3
CVE-2026-55968 HIGH
Apache Thrift: Node.js quadratic-time DoS in server receive transports
CVSS 7.5
CVE-2026-65623 HIGH
Quadratic CPU blow-up reassembling fragmented WebSocket messages in Bandit
CVE-2026-13064 MEDIUM
MongoDB $jsonSchema Query Operator Excessive CPU Consumption Leading to Denial of Service
CVSS 6.5
CVE-2026-59885 HIGH
pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service
CVSS 7.5
CVE-2026-57480 HIGH
Parse Server: Denial of service via exponential-time processing of deeply nested query operators
CVE-2026-56669 HIGH
Elysia: Inefficient Algorithmic Complexity and Interpretation Conflict
CVSS 7.5
CVE-2026-55206 HIGH
py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()
CVE-2026-59928 HIGH
Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
CVSS 7.5
CVE-2026-59925 HIGH
inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
CVSS 7.5
CVE-2026-59922 HIGH
Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
CVSS 7.5
CVE-2026-59887 HIGH
linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text
CVSS 7.5
CVE-2026-59880 HIGH
Immutable.js: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
CVSS 7.5
CVE-2026-59870 MEDIUM
js-yaml quadratic-complexity denial of service via YAML11_SCHEMA !!omap parsing
CVSS 5.3
CVE-2026-59869 HIGH
js-yaml: YAML merge-key chains can force quadratic CPU consumption
CVSS 7.5
CVE-2026-59868 MEDIUM
js-yaml: YAML merge-key chains can force quadratic CPU consumption
CVSS 5.3
CVE-2026-58226 HIGH
Unauthenticated denial-of-service via unbounded HPACK integer decoding in hpax
CVE-2026-59094 HIGH
Pathway - Unauthenticated Denial of Service via Exponential Glob Pattern Matching in Document Store
CVSS 7.5
CVE-2026-53433 HIGH
fzf < 0.73.1 --listen - HTTP Body Processing Denial of Service
CVSS 7.5
CVE-2026-13149 HIGH
Juliangruber Brace-expansion < 5.0.6 - Uncontrolled Resource Consumption
CVE-2026-45822 MEDIUM
Samverschueren Decode-uri-component < 0.5.0 - Uncontrolled Resource Consumption
CVE-2026-13311 HIGH
shell-quote parse() is quadratic in token count, enabling denial of service
CVSS 7.5
Details
Vulnerabilities 124
Exploit Likelihood Low