CWE-407

Low likelihood

Inefficient Algorithmic Complexity

Parent: CWE-405 - Asymmetric Resource Consumption (Amplification)

An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.

74 vulnerabilities with CWE-407
CVE-2026-40476 MEDIUM
graphql-php: Denial of Service via quadratic complexity in OverlappingFieldsCanBeMerged validation
CVE-2026-40164 HIGH
jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seed
CVSS 7.5
CVE-2026-35599 MEDIUM
Vikunja has an Algorithmic Complexity DoS in Repeating Task Handler
CVSS 6.5
CVE-2026-6042 LOW
musl libc GB18030 4-byte Decoder iconv.c iconv algorithmic complexity
CVSS 3.3
CVE-2026-33033 MEDIUM
Potential denial-of-service vulnerability in MultiPartParser via base64-encoded file upload
CVSS 6.5
CVE-2026-34827 HIGH
Rack: Algorithmic-Complexity DoS in Rack::Multipart::Parser
CVSS 7.5
CVE-2026-34230 MEDIUM
Rack: Quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header
CVSS 5.3
CVE-2026-31937 HIGH
Suricata dcerpc: quadratic complexity in dcerpc buffering
CVSS 7.5
CVE-2026-31934 HIGH
Suricata smtp/mine: quadratic complexity in extracting urls
CVSS 7.5
CVE-2026-31933 HIGH
Suricata stream: quadratic complexity in stream inspection
CVSS 7.5
CVE-2026-31932 HIGH
Suricata krb5: quadratic complexity in krb5 buffering
CVSS 7.5
CVE-2026-34573 HIGH
Parse Server: GraphQL complexity validator exponential fragment traversal DoS
CVSS 7.5
CVE-2026-3988 HIGH
Inefficient Algorithmic Complexity in GitLab
CVSS 7.5
CVE-2026-33123 MEDIUM
pypdf has inefficient decoding of array-based streams
CVSS 6.5
CVE-2026-28804 MEDIUM
pypdf <6.7.5 - DoS
CVSS 5.3
CVE-2026-27903 HIGH
minimatch <10.2.3 - DoS
CVSS 7.5
CVE-2026-1285 HIGH
Django <6.0.2-<4.2.28 - DoS
CVSS 7.5
CVE-2025-67841 HIGH
Nordic Semiconductor IronSide SE <23.0.2+17 - DoS
CVSS 7.5
CVE-2025-14831 MEDIUM
GnuTLS - DoS
CVSS 5.3
CVE-2025-14550 HIGH
Django <6.0.2-4.2.28 - DoS
CVSS 7.5
CVE-2025-14822 LOW
Mattermost <10.11.9 - DoS
CVSS 3.1
CVE-2025-12084 MEDIUM
xml.dom.minidom - Info Disclosure
CVSS 5.3
CVE-2025-64460 HIGH
Django <5.2.9-4.2.27 - DoS
CVSS 7.5
CVE-2025-66382 LOW
libexpat <2.7.3 - DoS
CVSS 2.9
CVE-2025-11230 HIGH
HAProxy - DoS
CVSS 7.5
Details
Vulnerabilities 74
Exploit Likelihood Low