CWE-1333
454 CVEs • Abstraction: Base • Likelihood of Exploit: High
Inefficient Regular Expression Complexity
The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.
CVEs (454)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Versions of the package semver before 7.5.2 are vulnerable to Regular Expression Denial of Service (ReDoS) via the function new Range, when untrusted user data is provided as a range.
|
1Git Url Parse Project 1Git Url Parse Jun 17, 2026 Jun 12, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The git-url-parse crate through 0.4.4 for Rust allows Regular Expression Denial of Service (ReDos) via a crafted URL to normalize_url in lib.rs, a similar issue to CVE-2023-32758 (Python). |
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.0 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression...Show more |
An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.7 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A Regular Expression D...Show more |
2Fast Xml Parser Project Naturalintelligence2Fast Xml Parser Fast Xml ParserJun 17, 2026 Jun 6, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 fast-xml-parser is an open source, pure javascript xml parser. fast-xml-parser allows special characters in entity names, which are not escaped or sanitized. Since the entity name is used for creating a regex for searchi...Show more |
A Regular Expression Denial of Service (ReDoS) issue was discovered in the sanitize_html function of redcloth gem v4.0.0. This vulnerability allows attackers to cause a Denial of Service (DoS) via supplying a crafted pay...Show more |
An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.10.8, all versions starting from 15.11 before 15.11.7, all versions starting from 16.0 before 16.0.2. A DollarMathPostFilte...Show more |
1Liferay 2Digital Experience Platform Liferay PortalJun 17, 2026 May 24, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Pattern Redirects in Liferay Portal 7.4.3.48 through 7.4.3.76, and Liferay DXP 7.4 update 48 through 76 allows regular expressions that are vulnerable to ReDoS attacks to be used as patterns, which allows remote attacker...Show more |
giturlparse (aka git-url-parse) through 1.2.2, as used in Semgrep 1.5.2 through 1.24.1, is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing untrusted URLs. This might be relevant if Semgrep is analyz...Show more |
1Puppet 2Puppet Enterprise Puppet ServerJun 17, 2026 May 4, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A Regular Expression Denial of Service (ReDoS) issue was discovered in Puppet Server 7.9.2 certificate validation. An issue related to specifically crafted certificate names significantly slowed down server operations. |
The Denosaurs emoji package provides emojis for dinosaurs. Starting in version 0.1.0 and prior to version 0.3.0, the reTrimSpace regex has 2nd degree polynomial inefficiency, leading to a delayed response given a big pay...Show more |
2Debian Sqlparse Project2Debian Linux SqlparseJun 17, 2026 Apr 18, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 sqlparse is a non-validating SQL parser module for Python. In affected versions the SQL parser contains a regular expression that is vulnerable to ReDoS (Regular Expression Denial of Service). This issue was introduced b...Show more |
Void Tools Everything lower than v1.4.1.1022 was discovered to contain a Regular Expression Denial of Service (ReDoS). |
All versions of the package configobj are vulnerable to Regular Expression Denial of Service (ReDoS) via the validate function, using (.+?)\((.*)\). **Note:** This is only exploitable in the case of a developer, putting...Show more |
3Debian FedoraprojectRuby Lang4Debian Linux FedoraRuby+1 moreJun 17, 2026 Mar 31, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A ReDoS issue was discovered in the Time component through 0.2.1 in Ruby through 3.2.1. The Time parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings t...Show more |
3Debian FedoraprojectRuby Lang3Debian Linux FedoraUriJun 17, 2026 Mar 31, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A ReDoS issue was discovered in the URI component through 0.12.0 in Ruby through 3.2.1. The URI parser mishandles invalid URLs that have specific characters. It causes an increase in execution time for parsing strings to...Show more |
2Angularjs Fedoraproject2Angularjs FedoraJun 17, 2026 Mar 30, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Versions of the package angular from 1.4.9 are vulnerable to Regular Expression Denial of Service (ReDoS) via the <input type="url"> element due to the usage of an insecure regular expression in the input[url] functional...Show more |
2Angularjs Fedoraproject2Angularjs FedoraJun 17, 2026 Mar 30, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Versions of the package angular from 1.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the $resource service due to the usage of an insecure regular expression. Exploiting this vulnerability is pos...Show more |
2Angularjs Fedoraproject2Angularjs FedoraJun 17, 2026 Mar 30, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Versions of the package angular from 1.2.21 are vulnerable to Regular Expression Denial of Service (ReDoS) via the angular.copy() utility function due to the usage of an insecure regular expression. Exploiting this vulne...Show more |
Versions of the package deno before 1.31.0 are vulnerable to Regular Expression Denial of Service (ReDoS) due to the upgradeWebSocket function, which contains regexes in the form of /s*,s*/, used for splitting the Connec...Show more |