CWE-1333
485 CVEs • Abstraction: Base • Likelihood of Exploit: High
Inefficient Regular Expression Complexity
The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.
CVEs (485)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Fedoraproject Marked Project2Fedora MarkedJun 17, 2026 Jan 14, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `inline.reflinkSearch` may cause catastrophic backtracking against some strings and lead to a denial of service (DoS). Anyone who...Show more |
2Fedoraproject Marked Project2Fedora MarkedJun 17, 2026 Jan 14, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Marked is a markdown parser and compiler. Prior to version 4.0.10, the regular expression `block.def` may cause catastrophic backtracking against some strings and lead to a regular expression denial of service (ReDoS). A...Show more |
1Markdown It Project 1Markdown It Jun 17, 2026 Jan 10, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 markdown-it is a Markdown parser. Prior to version 1.3.2, special patterns with length greater than 50 thousand characterss could slow down the parser significantly. Users should upgrade to version 12.3.2 to receive a pa...Show more |
3Debian FedoraprojectNltk3Debian Linux FedoraNltkJun 17, 2026 Jan 4, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 nltk is vulnerable to Inefficient Regular Expression Complexity |
6Debian FedoraprojectOpensuse+3 more9Date Debian LinuxEnterprise Linux+6 moreJun 17, 2026 Jan 1, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Date.parse in the date gem through 3.2.0 for Ruby allows ReDoS (regular expression Denial of Service) via a long string. The fixed versions are 3.2.1, 3.1.2, 3.0.2, and 2.0.1. |
1Parse Link Header Project 1Parse Link Header Jun 17, 2026 Dec 24, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 The package parse-link-header before 2.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the checkHeader function. |
lib/DatabaseLayer.py in cve-search before 4.1.0 allows regular expression injection, which can lead to ReDoS (regular expression denial of service) or other impacts. |
jsx-slack is a package for building JSON objects for Slack block kit surfaces from JSX. The maintainers found the patch for CVE-2021-43838 in jsx-slack v4.5.1 is insufficient tfor protection from a Regular Expression Den...Show more |
jsx-slack is a library for building JSON objects for Slack Block Kit surfaces from JSX. In versions prior to 4.5.1 users are vulnerable to a regular expression denial-of-service (ReDoS) attack. If attacker can put a lot...Show more |
An issue has been discovered in GitLab CE/EE affecting all versions starting from 13.2 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. GitLab Maven Package reg...Show more |
An issue has been discovered in GitLab CE/EE affecting all versions starting from 12.10 before 14.3.6, all versions starting from 14.4 before 14.4.4, all versions starting from 14.5 before 14.5.2. A regular expression us...Show more |
Solidus is a free, open-source ecommerce platform built on Rails. Versions of Solidus prior to 3.1.4, 3.0.4, and 2.11.13 have a denial of service vulnerability that could be exploited during a guest checkout. The regular...Show more |
validator.js is vulnerable to Inefficient Regular Expression Complexity |
Zulip is an open source team chat server. In affected versions Zulip allows organization administrators on a server to configure "linkifiers" that automatically create links from messages that users send, detected via ar...Show more |
The package handsontable before 10.0.0; the package handsontable from 0 and before 10.0.0 are vulnerable to Regular Expression Denial of Service (ReDoS) in Handsontable.helper.isNumeric function. |
nltk is vulnerable to Inefficient Regular Expression Complexity |
jsoneditor is vulnerable to Inefficient Regular Expression Complexity |
inflect is vulnerable to Inefficient Regular Expression Complexity |
code-server is vulnerable to Inefficient Regular Expression Complexity |
2Ansi Regex Project Oracle2Ansi Regex Communications Cloud Native Core PolicyJun 17, 2026 Sep 17, 2021 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 ansi-regex is vulnerable to Inefficient Regular Expression Complexity |