← Back
CWE-1333

485 CVEs • Abstraction: Base • Likelihood of Exploit: High

Inefficient Regular Expression Complexity

The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.

JSON object

Loading...

CVEs (485)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Fedoraproject
Marked Project
2Fedora
Marked
Jun 17, 2026
Jan 14, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `inline.reflinkSearch` may cause catastrophic backtracking against some strings and lead to a denial of service (DoS). Anyone who...Show more
Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `inline.reflinkSearch` may cause catastrophic backtracking against some strings and lead to a denial of service (DoS). Anyone who runs untrusted markdown through a vulnerable version of marked and does not use a worker with a time limit may be affected. This issue is patched in version 4.0.10. As a workaround, avoid running untrusted markdown through marked or run marked on a worker thread and set a reasonable time limit to prevent draining resources.Show less
2Fedoraproject
Marked Project
2Fedora
Marked
Jun 17, 2026
Jan 14, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `block.def` may cause catastrophic backtracking against some strings and lead to a regular expression denial of service (ReDoS). A...Show more
Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `block.def` may cause catastrophic backtracking against some strings and lead to a regular expression denial of service (ReDoS). Anyone who runs untrusted markdown through a vulnerable version of marked and does not use a worker with a time limit may be affected. This issue is patched in version 4.0.10. As a workaround, avoid running untrusted markdown through marked or run marked on a worker thread and set a reasonable time limit to prevent draining resources.Show less
1Markdown It Project
1Markdown It
Jun 17, 2026
Jan 10, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
markdown-it is a Markdown parser. Prior to version 1.3.2, special patterns with length greater than 50 thousand characterss could slow down the parser significantly. Users should upgrade to version 12.3.2 to receive a pa...Show more
markdown-it is a Markdown parser. Prior to version 1.3.2, special patterns with length greater than 50 thousand characterss could slow down the parser significantly. Users should upgrade to version 12.3.2 to receive a patch. There are no known workarounds aside from upgrading.Show less
3Debian
FedoraprojectNltk
3Debian Linux
FedoraNltk
Jun 17, 2026
Jan 4, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
nltk is vulnerable to Inefficient Regular Expression Complexity
6Debian
FedoraprojectOpensuse+3 more
9Date
Debian LinuxEnterprise Linux+6 more
Jun 17, 2026
Jan 1, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1.
1Parse Link Header Project
1Parse Link Header
Jun 17, 2026
Dec 24, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The package parse-link-header before 2.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the checkHeader function.
1Circl
1Cve Search
Jun 17, 2026
Dec 23, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
lib/DatabaseLayer.py in cve-search before 4.1.0 allows regular expression injection, which can lead to ReDoS (regular expression denial of service) or other impacts.
1Jsx Slack Project
1Jsx Slack
Jun 17, 2026
Dec 20, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
jsx-slack is a package for building JSON objects for Slack block kit surfaces from JSX. The maintainers found the patch for CVE-2021-43838 in jsx-slack v4.5.1 is insufficient tfor protection from a Regular Expression Den...Show more
jsx-slack is a package for building JSON objects for Slack block kit surfaces from JSX. The maintainers found the patch for CVE-2021-43838 in jsx-slack v4.5.1 is insufficient tfor protection from a Regular Expression Denial of Service (ReDoS) attack. If an attacker can put a lot of JSX elements into `<blockquote>` tag _with including multibyte characters_, an internal regular expression for escaping characters may consume an excessive amount of computing resources. v4.5.1 passes the test against ASCII characters but misses the case of multibyte characters. jsx-slack v4.5.2 has updated regular expressions for escaping blockquote characters to prevent catastrophic backtracking. It is also including an updated test case to confirm rendering multiple tags in `<blockquote>` with multibyte characters.Show less
1Jsx Slack Project
1Jsx Slack
Jun 17, 2026
Dec 17, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
jsx-slack is a library for building JSON objects for Slack Block Kit surfaces from JSX. In versions prior to 4.5.1 users are vulnerable to a regular expression denial-of-service (ReDoS) attack. If attacker can put a lot...Show more
jsx-slack is a library for building JSON objects for Slack Block Kit surfaces from JSX. In versions prior to 4.5.1 users are vulnerable to a regular expression denial-of-service (ReDoS) attack. If attacker can put a lot of JSX elements into `<blockquote>` tag, an internal regular expression for escaping characters may consume an excessive amount of computing resources. jsx-slack v4.5.1 has patched to a regex for escaping blockquote characters. Users are advised to upgrade as soon as possible.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Dec 13, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab Maven Package reg...Show more
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab Maven Package registry is vulnerable to a regular expression denial of service when a specifically crafted string is sent.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Dec 13, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression us...Show more
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression used for handling user input (notes, comments, etc) was susceptible to catastrophic backtracking that could cause a DOS attack.Show less
1Nebulab
1Solidus
Jun 17, 2026
Dec 7, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
Solidus is a free, open-source ecommerce platform built on Rails. Versions of Solidus prior to 3.1.4, 3.0.4, and 2.11.13 have a denial of service vulnerability that could be exploited during a guest checkout. The regular...Show more
Solidus is a free, open-source ecommerce platform built on Rails. Versions of Solidus prior to 3.1.4, 3.0.4, and 2.11.13 have a denial of service vulnerability that could be exploited during a guest checkout. The regular expression used to validate a guest order's email was subject to exponential backtracking through a fragment like `a.a.` Versions 3.1.4, 3.0.4, and 2.11.13 have been patched to use a different regular expression. The maintainers added a check for email addresses that are no longer valid that will print information about any affected orders that exist. If a prompt upgrade is not an option, a workaround is available. It is possible to edit the file `config/application.rb` manually (with code provided by the maintainers in the GitHub Security Advisory) to check email validity.Show less
1Validator Project
1Validator
Jun 17, 2026
Nov 2, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
validator.js is vulnerable to Inefficient Regular Expression Complexity
1Zulip
1Zulip
Jun 17, 2026
Oct 7, 2021
N/A· v4
6.5 MEDIUM· v3
4.0 MEDIUM· v2
Zulip is an open source team chat server. In affected versions Zulip allows organization administrators on a server to configure "linkifiers" that automatically create links from messages that users send, detected via ar...Show more
Zulip is an open source team chat server. In affected versions Zulip allows organization administrators on a server to configure "linkifiers" that automatically create links from messages that users send, detected via arbitrary regular expressions. Malicious organization administrators could subject the server to a denial-of-service via regular expression complexity attacks; most simply, by configuring a quadratic-time regular expression in a linkifier, and sending messages that exploited it. A regular expression attempted to parse the user-provided regexes to verify that they were safe from ReDoS -- this was both insufficient, as well as _itself_ subject to ReDoS if the organization administrator entered a sufficiently complex invalid regex. Affected users should [upgrade to the just-released Zulip 4.7](https://zulip.readthedocs.io/en/latest/production/upgrade-or-modify.html#upgrading-to-a-release), or [`main`](https://zulip.readthedocs.io/en/latest/production/upgrade-or-modify.html#upgrading-from-a-git-repository).Show less
1Handsontable
1Handsontable
Jun 17, 2026
Sep 29, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The package handsontable before 10.0.0; the package handsontable from 0 and before 10.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) in Handsontable.helper.isNumeric function.
1Nltk
1Nltk
Jun 17, 2026
Sep 27, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
nltk is vulnerable to Inefficient Regular Expression Complexity
1Jsoneditoronline
1Jsoneditor
Jun 17, 2026
Sep 27, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
jsoneditor is vulnerable to Inefficient Regular Expression Complexity
1Inflect Project
1Inflect
Jun 17, 2026
Sep 27, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
inflect is vulnerable to Inefficient Regular Expression Complexity
1Coder
1Code Server
Jun 17, 2026
Sep 17, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
code-server is vulnerable to Inefficient Regular Expression Complexity
2Ansi Regex Project
Oracle
2Ansi Regex
Communications Cloud Native Core Policy
Jun 17, 2026
Sep 17, 2021
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
ansi-regex is vulnerable to Inefficient Regular Expression Complexity