CWE-407
Low likelihoodInefficient Algorithmic Complexity
An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.
124 vulnerabilities with CWE-407
CVE-2026-49851
HIGH
Mistune: Potential DoS via quadratic-time parsing in parse_link_text
CVSS 7.5
CVE-2026-54892
HIGH
Plug: quadratic-time decoding of nested query/body parameters enables denial of service
CVE-2026-48516
HIGH
MessagePack-CSharp: InterfaceLookupFormatter bypasses collision-resistant comparer settings
CVSS 7.5
CVE-2026-48511
HIGH
MessagePack-CSharp: ExpandoObject formatter can perform quadratic insertion work on untrusted maps
CVSS 7.5
CVE-2026-48502
HIGH
MessagePack-CSharp ReadDateTime - Stack Overflow Denial of Service
CVSS 7.5
CVE-2026-49460
LOW
pypdf: Inefficient decoding of FlateDecode PNG predictor streams
CVSS 3.3
CVE-2026-53539
HIGH
Python-Multipart: Quadratic-time querystring parsing with semicolon separators causes CPU denial of service
CVSS 7.5
CVE-2026-53550
MEDIUM
js-yaml: Quadratic-complexity DoS in merge key handling via repeated aliases
CVSS 5.3
CVE-2026-49293
HIGH
CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals
CVSS 7.5
CVE-2026-45664
MEDIUM
ImageMagick: Policy Bypass in MNG coder could
CVSS 5.3
CVE-2026-41850
HIGH
Spring Framework Algorithmic Denial of Service via SpEL Expressions
CVSS 7.5
CVE-2026-11312
LOW
bytedance InfiniStore KV Map infinistore.h purge_kv_map algorithmic complexity
CVSS 3.3
CVE-2026-8889
HIGH
Securly Chrome Extension < 3.0.7 - Weak Hashing via SHA-1
CVSS 7.5
CVE-2026-3276
MEDIUM
Python Software Foundation CPython - Potential DoS via Quadratic Complexity in unicodedata.normalize()
CVE-2026-42504
HIGH
Quadratic complexity in WordDecoder.DecodeHeader in mime
CVSS 7.5
CVE-2026-8594
MEDIUM
Text::LineFold versions through 2019.001 for Perl duplicate the output based on the number of special break characters
CVSS 6.2
CVE-2026-44378
HIGH
Botan: Quadratic complexity decoding BER indefinite length encodings
CVSS 7.5
CVE-2026-48959
HIGH
IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward
CVSS 7.5
CVE-2026-44390
MEDIUM
Unbounded name compression in certain cases causes degradation of service
CVSS 5.3
CVE-2026-42923
MEDIUM
NLnet Labs Unbound - Degradation of Service with Unbounded NSEC3 Hash Calculations
CVSS 5.3
CVE-2026-41292
HIGH
Unbound <= 1.25.0 - Denial of Service via EDNS Option Parsing
CVSS 7.5
CVE-2026-42304
HIGH
Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Chains
CVSS 7.5
CVE-2026-45186
LOW
libexpat < 2.8.1 - Denial of Service via Attribute Name Collision Checks
CVSS 2.9
CVE-2026-42245
HIGH
net-imap: Quadratic complexity when reading response literals
CVSS 7.5
CVE-2026-43967
HIGH
Quadratic fragment-name uniqueness check causes denial of service in absinthe
CVSS 7.5
Details
Vulnerabilities
124
Exploit Likelihood
Low