CWE-407
Low likelihoodInefficient Algorithmic Complexity
An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.
124 vulnerabilities with CWE-407
CVE-2026-40476
HIGH
graphql-php: Denial of Service via quadratic complexity in OverlappingFieldsCanBeMerged validation
CVSS 7.5
CVE-2026-40164
HIGH
jq: Algorithmic complexity DoS via hardcoded MurmurHash3 seed
CVSS 7.5
CVE-2026-35599
MEDIUM
Vikunja <2.3.0 Repeating Task Handler - Denial of Service
CVSS 6.5
CVE-2026-6042
LOW
musl libc GB18030 4-byte Decoder iconv.c iconv algorithmic complexity
CVSS 3.3
CVE-2026-33033
MEDIUM
Django < 6.0.4, 5.2.13, 4.2.30 - MultiPartParser Base64 Upload Denial of Service
CVSS 6.5
CVE-2026-34827
HIGH
Rack: Algorithmic-Complexity DoS in Rack::Multipart::Parser
CVSS 7.5
CVE-2026-34230
MEDIUM
Rack: Quadratic complexity in Rack::Utils.select_best_encoding via wildcard Accept-Encoding header
CVSS 5.3
CVE-2026-31937
HIGH
Suricata dcerpc: quadratic complexity in dcerpc buffering
CVSS 7.5
CVE-2026-31934
HIGH
Suricata smtp/mine: quadratic complexity in extracting urls
CVSS 7.5
CVE-2026-31933
HIGH
Suricata stream: quadratic complexity in stream inspection
CVSS 7.5
CVE-2026-31932
HIGH
Suricata krb5: quadratic complexity in krb5 buffering
CVSS 7.5
CVE-2026-34573
HIGH
Parse Server: GraphQL complexity validator exponential fragment traversal DoS
CVSS 7.5
CVE-2026-3988
HIGH
Inefficient Algorithmic Complexity in GitLab
CVSS 7.5
CVE-2026-33123
MEDIUM
pypdf has inefficient decoding of array-based streams
CVSS 6.5
CVE-2026-28804
MEDIUM
pypdf < 6.7.5 - Denial of Service via ASCIIHexDecode Filter
CVSS 5.3
CVE-2026-27903
HIGH
minimatch < 10.2.3 DoS via Globstar Pattern Backtracking
CVSS 7.5
CVE-2026-1285
HIGH
Django 4.2-4.2.27, 5.2-5.2.10, 6.0-6.0.1 - Denial of Service via Unmatched HTML End Tags
CVSS 7.5
CVE-2025-67841
HIGH
Nordic Semiconductor IronSide SE <23.0.2+17 - DoS
CVSS 7.5
CVE-2025-14831
MEDIUM
GnuTLS - Denial of Service
CVSS 5.3
CVE-2025-14550
HIGH
Django 4.2-4.2.27, 5.2-5.2.10, 6.0-6.0.1 - Denial of Service via Duplicate ASGI Headers
CVSS 7.5
CVE-2025-14822
LOW
Mattermost 10.11.0-10.11.8 - Authenticated Denial of Service via Hashtag Processing
CVSS 3.1
CVE-2025-12084
MEDIUM
Python < 3.13.11 - Denial of Service via Quadratic Complexity in xml.dom.minidom
CVSS 5.3
CVE-2025-64460
HIGH
Django 4.2-4.2.26 5.1-5.1.14 5.2a1-5.2.8 - Denial of Service via XML Deserializer
CVSS 7.5
CVE-2025-66382
LOW
libexpat < 2.7.3 - Denial of Service via Crafted File Processing
CVSS 2.9
CVE-2025-11230
HIGH
HAProxy Aloha Appliance 14.5.0-14.5.32 and HAProxy 2.4.0-2.4.29 - Denial of Service via mjson JSON Request Parsing
CVSS 7.5
Details
Vulnerabilities
124
Exploit Likelihood
Low