CVE-2021-3807High· 7.5▾ Twilightansi-regex is vulnerable to Inefficient Regular Expression Complexity
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.7 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
3.6%
ansi-regex is vulnerable to Inefficient Regular Expression Complexity
ansi-regex >= 4.0.0, < 4.1.1ansi-regex = 3.0.0ansi-regex = 5.0.0ansi-regex = 6.0.0communications_cloud_native_core_policy = 1.15.0Upgrade past the affected range:
ansi-regex 4.1.1Connected by shared product, vendor, weakness, or advisory.
CVE-2024-21538High· 7.5Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization
CVE-2024-21490High· 7.5This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0
CVE-2026-104628Medium· 6.5Satel Netco Design versions prior to v2.1.7 contains an inefficient regular expression complexity vulnerability
CVE-2026-107290Medium· 6.5Pydantic AI is a Python agent framework for building applications and workflows with Generative AI
CVE-2026-62237Medium· 6.5Grav before 2.0.4 contains a regular expression denial of service (ReDoS) vulnerability in the regex_replace filter and function, which are allowlisted in the Twig content sandbox
CVE-2026-107572Medium· 6.5Inefficient complexity in the Sieve filter evaluation of Progressive Robot hMailServer 6.2.24 through 6.3.5 allows an authenticated account holder to make the mail services unavailable with their own filter