CWE-1333
Inefficient Regular Expression Complexity (ReDoS)
MITRENo catalog description on file. The MITRE CWE site has the canonical reference.
Recent CVEs
showing 8 of 8- CVE-2026-47138—EPSS 0%17 h ago
Parse Server: Pre-authentication denial of service via client version header regex backtracking
npm - CVE-2026-44496High· 7.5EPSS 0%22 h ago
Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metachar
npm - CVE-2026-42567High· 7.5EPSS 0%1 d ago
Svelte is a performance oriented web framework. From version 5.51.5 to before version 5.55.7, an internal regex in the Svelte runtime can take exponential time to test in <svelte:element this={tag}></svelte:element>. This issue has been pat
npm - CVE-2026-41848Low· 3.7EPSS 0%2 d ago
Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(Strin
- CVE-2026-52778Critical· 9.8EPSS 0%3 d ago
YesWiki is a wiki system written in PHP. Prior to version 4.6.6, an unsafe execution vulnerability exists in the Bazar form field calculator (CalcField.php) of YesWiki. The application attempts to sanitize user-defined mathematical formulas
- CVE-2026-45409—EPSS 0%4 d ago
Internationalized Domain Names in Applications (IDNA): Specially crafted inputs to idna.encode() can bypass CVE-2024-3651 fix
pypi - CVE-2026-11478Low· 3.3EPSS 0%5 d ago
A flaw has been found in kokke tiny-regex-c up to f2632c6d9ed25272987471cdb8b70395c2460bdb. This vulnerability affects the function matchstar of the file re.c of the component Pattern Handler. This manipulation causes inefficient regular ex
- CVE-2026-8888High· 7.5EPSS 0%7 d ago
Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions via new RegExp() without complexity validation. An on-path attacker can inject specific pa
CWE catalog data sourced from MITRE. CVE associations come from NVD weakness mappings; some CVEs carry multiple CWEs.