---
id: CVE-2026-57577
title: DotVVM is an open source MVVM framework for web applications
summary: >-
  DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11,
  4.3.15, and 5.0.0-preview09-final, a route containing multiple unconstrained
  parameters in one path segment can cause excessive regular-expression
  backtrackin…
severity: high
cvss: 8.2
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-1333
vendor: riganti
product: dotvvm
affected:
  - dotvvm < 4.2.11
  - 'dotvvm >= 4.3.0, < 4.3.15'
  - 'dotvvm >= 5.0.0-preview01, < 5.0.0-preview09-final'
published: '2026-09-14'
updated: '2026-09-14'
sourceUpdated: '2026-09-14T18:17:57.353'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-57577'
references:
  - url: >-
      https://github.com/riganti/dotvvm/commit/1635245b5eaf9ccf8e3536b9d8b1941819526585
    label: security-advisories@github.com
  - url: >-
      https://github.com/riganti/dotvvm/commit/4fc26a8591c76fb92ed701352c2a84120cf926c5
    label: security-advisories@github.com
  - url: >-
      https://github.com/riganti/dotvvm/commit/5728ab80fff9af883b44d11c118d2e8a8991dcd4
    label: security-advisories@github.com
  - url: 'https://github.com/riganti/dotvvm/releases/tag/v4.3.15'
    label: security-advisories@github.com
  - url: 'https://github.com/riganti/dotvvm/releases/tag/v5.0.0-preview09'
    label: security-advisories@github.com
  - url: 'https://github.com/riganti/dotvvm/security/advisories/GHSA-c2g3-c4gc-w5wg'
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T17:54:17.670075Z'
cvssSource: cna
ingestedAt: '2026-09-14T19:13:23.458Z'
epss: 0.00577
epssPercentile: 0.452
---

## Overview

DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, a route containing multiple unconstrained parameters in one path segment can cause excessive regular-expression backtracking in DotvvmRoute.IsMatch when a remote requester supplies a long near-match path. DotvvmRouteParser.RouteRegex previously had no matching timeout. Patched runtimes retry with the .NET non-backtracking engine, while runtimes that do not support non-backtracking matching return HTTP 503 after the one-second timeout in DotvvmRoutingMiddleware. This issue is fixed in versions 4.2.11, 4.3.15, and 5.0.0-preview09-final.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
