CWE-1333
454 CVEs • Abstraction: Base • Likelihood of Exploit: High
Inefficient Regular Expression Complexity
The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.
CVEs (454)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Solidus is a free, open-source ecommerce platform built on Rails. Versions of Solidus prior to 3.1.4, 3.0.4, and 2.11.13 have a denial of service vulnerability that could be exploited during a guest checkout. The regular...Show more |
validator.js is vulnerable to Inefficient Regular Expression Complexity |
Zulip is an open source team chat server. In affected versions Zulip allows organization administrators on a server to configure "linkifiers" that automatically create links from messages that users send, detected via ar...Show more |
The package handsontable before 10.0.0; the package handsontable from 0 and before 10.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) in Handsontable.helper.isNumeric function. |
nltk is vulnerable to Inefficient Regular Expression Complexity |
jsoneditor is vulnerable to Inefficient Regular Expression Complexity |
inflect is vulnerable to Inefficient Regular Expression Complexity |
code-server is vulnerable to Inefficient Regular Expression Complexity |
2Ansi Regex Project Oracle2Ansi Regex Communications Cloud Native Core PolicyJun 17, 2026 Sep 17, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 ansi-regex is vulnerable to Inefficient Regular Expression Complexity |
taro is vulnerable to Inefficient Regular Expression Complexity |
2Debian Nth Check Project2Debian Linux Nth CheckJun 17, 2026 Sep 17, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 nth-check is vulnerable to Inefficient Regular Expression Complexity |
1Semver Regex Project 1Semver Regex Jun 17, 2026 Sep 15, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 semver-regex is vulnerable to Inefficient Regular Expression Complexity |
prism is vulnerable to Inefficient Regular Expression Complexity |
vuelidate is vulnerable to Inefficient Regular Expression Complexity |
nodejs-tmpl is vulnerable to Inefficient Regular Expression Complexity |
3Axios OracleSiemens3Axios GoldengateSinec InsJun 17, 2026 Aug 31, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 axios is vulnerable to Inefficient Regular Expression Complexity |
chatwoot is vulnerable to Inefficient Regular Expression Complexity |
A regular expression denial of service (ReDoS) vulnerability in the validateBaseUrl function can cause the application to use excessive resources, become unresponsive, or crash. This was introduced in react-native versio...Show more |
1Normalize Url Project 1Normalize Url Jun 17, 2026 May 24, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The normalize-url package before 4.5.1, 5.x before 5.3.1, and 6.x before 6.0.1 for Node.js has a ReDoS (regular expression denial of service) issue because it has exponential performance for data: URLs. |
1Browserslist Project 1Browserslist Jun 17, 2026 Apr 28, 2021 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The package browserslist from 4.0.0 and before 4.16.5 are vulnerable to Regular Expression Denial of Service (ReDoS) during parsing of queries. |