CWE-407
Low likelihoodInefficient Algorithmic Complexity
An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.
124 vulnerabilities with CWE-407
CVE-2026-67216
MEDIUM
cJSON cJSON_Compare Exponential Complexity Denial of Service
CVSS 5.9
CVE-2026-6879
LOW
Python Software Foundation CPython - Quadratic Behavior in xml.etree.ElementPath Index Predicates
CVE-2026-55685
HIGH
React Router: Unauthenticated Denial of Service via Inefficient Route Matching
CVE-2026-64644
MEDIUM
Next.js: Denial of Service in the Image Optimization API using SVGs
CVSS 5.3
CVE-2026-55968
HIGH
Apache Thrift: Node.js quadratic-time DoS in server receive transports
CVSS 7.5
CVE-2026-65623
HIGH
Quadratic CPU blow-up reassembling fragmented WebSocket messages in Bandit
CVE-2026-13064
MEDIUM
MongoDB $jsonSchema Query Operator Excessive CPU Consumption Leading to Denial of Service
CVSS 6.5
CVE-2026-59885
HIGH
pyasn1: Quadratic complexity in OBJECT IDENTIFIER and RELATIVE-OID processing allows denial of service
CVSS 7.5
CVE-2026-57480
HIGH
Parse Server: Denial of service via exponential-time processing of deeply nested query operators
CVE-2026-56669
HIGH
Elysia: Inefficient Algorithmic Complexity and Interpretation Conflict
CVSS 7.5
CVE-2026-55206
HIGH
py7zr: O(n^2) algorithmic complexity DoS in PackInfo._read()
CVE-2026-59928
HIGH
Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
CVSS 7.5
CVE-2026-59925
HIGH
inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
CVSS 7.5
CVE-2026-59922
HIGH
Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
CVSS 7.5
CVE-2026-59887
HIGH
linkify-it: Quadratic-complexity DoS via the `mailto:` validator scan-loop on attacker text
CVSS 7.5
CVE-2026-59880
HIGH
Immutable.js: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
CVSS 7.5
CVE-2026-59870
MEDIUM
js-yaml quadratic-complexity denial of service via YAML11_SCHEMA !!omap parsing
CVSS 5.3
CVE-2026-59869
HIGH
js-yaml: YAML merge-key chains can force quadratic CPU consumption
CVSS 7.5
CVE-2026-59868
MEDIUM
js-yaml: YAML merge-key chains can force quadratic CPU consumption
CVSS 5.3
CVE-2026-58226
HIGH
Unauthenticated denial-of-service via unbounded HPACK integer decoding in hpax
CVE-2026-59094
HIGH
Pathway - Unauthenticated Denial of Service via Exponential Glob Pattern Matching in Document Store
CVSS 7.5
CVE-2026-53433
HIGH
fzf < 0.73.1 --listen - HTTP Body Processing Denial of Service
CVSS 7.5
CVE-2026-13149
HIGH
Juliangruber Brace-expansion < 5.0.6 - Uncontrolled Resource Consumption
CVE-2026-45822
MEDIUM
Samverschueren Decode-uri-component < 0.5.0 - Uncontrolled Resource Consumption
CVE-2026-13311
HIGH
shell-quote parse() is quadratic in token count, enabling denial of service
CVSS 7.5
Details
Vulnerabilities
124
Exploit Likelihood
Low