VulnSea

CWE-1333

CVEs classified under CWE-1333, newest first.

101 CVEsRSS

CVE-2026-59220Medium· 6.5
2mo ago

Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config

Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config

▾ Sunlitopen-webui · open-webuiEPSS 0.57%via GHSA
CVE-2026-58436High
2mo ago

Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests

Gitea: ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests

▾ Twilightgitea · code.gitea.io/giteaEPSS 0.61%via GHSA
CVE-2026-45367High· 7.5
2mo ago

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.7, the FHIRPathEngine implementation passes user-controlled regular expressions from matches(), matchesFull(), and repl…

▾ TwilightEPSS 0.68%via NVD
CVE-2026-49477High· 7.5
2mo ago

soupsieve: Soupsieve: Denial of Service via crafted CSS selector strings (CVE-2026-49477)

A flaw was found in soupsieve, a CSS selector library. This vulnerability allows a remote attacker to cause a Denial of Service (DoS) by supplying specially crafted, untrusted CSS selector strings. The flaw occurs due to a regular expressi…

▾ TwilightRed Hat · Red Hat OpenShift AI 3.4EPSS 0.64%via CSAF
CVE-2026-48801High· 7.5
2mo ago

linkify-it: linkify-it: Denial of Service via algorithmic complexity vulnerability (CVE-2026-48801)

A flaw was found in linkify-it, a library for recognizing links with full Unicode support. The LinkifyIt.prototype.match function, the package's primary public API, has an algorithmic complexity of O(N²) for inputs containing many fuzzy li…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.18EPSS 0.52%via CSAF
CVE-2026-6850Medium· 6.5
2mo ago

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of message attachment field values, which allows an authenticated attacker to cause a denial of service for all users in …

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of message attachment field values, which allows an authenticated attacker to cause a denial of service for all users in …

▾ SunlitEPSS 0.42%via NVD
CVE-2026-57584None
2mo ago

Phalcon is a high-performance, full-stack PHP framework

Phalcon is a high-performance, full-stack PHP framework. Prior to 5.15.0, every Phalcon MVC application built with a default router registers a built-in route whose compiled PCRE pattern contains the nested quantifier (/.), and the same …

▾ SunlitEPSS 0.52%via NVD
CVE-2026-49851High· 7.5
2mo ago

Mistune: Potential DoS via quadratic-time parsing in parse_link_text

Mistune: Potential DoS via quadratic-time parsing in parse_link_text

▾ Twilightmistune · mistuneEPSS 0.63%via OSV
CVE-2026-52778Critical· 9.8
2mo ago

YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of Service

YesWiki has Unsafe eval() in its Formula Calculato, Leading to Remote Code Execution & Denial of Service

▾ Midnightyeswiki · yeswiki/yeswikiEPSS 0.94%via GHSA
CVE-2026-49485High· 7.5
2mo ago

org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint

org.hl7.fhir.core: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint

▾ Twilightuhn · ca.uhn.hapi.fhir:org.hl7.fhir.dstu2EPSS 0.68%via GHSA
CVE-2026-15154Medium· 6.5
2mo ago

A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI

A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (ReDoS), allows a remote attacker to provide specially crafted regular expressions to the …

▾ Sunlitredhat · openshift_aiEPSS 0.46%via NVD
CVE-2026-59887High· 7.5
2mo ago

linkify-it: linkify-it: Denial of Service via crafted mailto: links (CVE-2026-59887)

A flaw was found in linkify-it, a library for recognizing links. A remote attacker could exploit this vulnerability by providing specially crafted user text. The mailto: schema validator, when processing this input, can be repeatedly invok…

▾ TwilightRed Hat · Red Hat OpenShift Dev Spaces 3.30EPSS 0.64%via CSAF
CVE-2026-55574High· 7.5
2mo ago

vllm: vLLM: Denial of Service via adversarial regular expression in structured outputs API (CVE-2026-55574)

A flaw was found in vLLM, a high-throughput and memory-efficient inference and serving engine for large language models (LLMs). A remote attacker could exploit this vulnerability by providing a specially crafted regular expression to the s…

▾ TwilightRed Hat · Red Hat AI Inference Server 3.4EPSS 0.58%via CSAF
CVE-2026-52746High· 7.5
2mo ago

jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion

jsonata: Malicious inputs to "$toMillis" function can cause resource exhaustion

▾ Twilightjsonata · jsonataEPSS 0.69%via GHSA
GHSA-x4hg-hfwf-p9mwMedium
2mo ago

@asymmetric-effort/nogginlessdom vulnerable to ReDoS via user-controlled regex in HTMLInputElement pattern validation

@asymmetric-effort/nogginlessdom vulnerable to ReDoS via user-controlled regex in HTMLInputElement pattern validation

▾ Sunlitasymmetric-effort · @asymmetric-effort/nogginlessdomvia GHSA
CVE-2026-13149High· 7.5
2mo ago

brace-expansion: Brace-expansion: Denial of Service due to exponential-time complexity (CVE-2026-13149)

A flaw was found in brace-expansion. An attacker can exploit a vulnerability in the `expand()` function by providing a specially crafted string. This string, containing consecutive non-expanding brace groups, can trigger exponential-time c…

▾ TwilightRed Hat · Red Hat Openshift Data Foundation 4.20EPSS 0.36%via CSAF
CVE-2026-49293High· 7.5
3mo ago

js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals

js-toml vulnerable to CPU exhaustion via O(n^2) BigInt construction on radix-prefixed integer literals

▾ Twilightjs-toml · js-tomlEPSS 0.64%via GHSA
CVE-2026-53550Medium· 5.3
3mo ago

js-yaml: js-yaml: Denial of Service via crafted YAML merge keys (CVE-2026-53550)

A flaw was found in js-yaml, a JavaScript YAML parser and dumper. A remote attacker can exploit this vulnerability by providing a specially crafted YAML document that repeatedly uses the same alias in a merge sequence. This can lead to alg…

▾ SunlitRed Hat · Red Hat Openshift Data Foundation 4.18EPSS 0.41%via CSAF
GHSA-vfm7-4h43-gp6mMedium· 4.3
3mo ago

Duplicate Advisory: vLLM Vulnerable to Regular Expression Denial of Service

Duplicate Advisory: vLLM Vulnerable to Regular Expression Denial of Service

▾ Sunlitvllm · vllmvia GHSA
GHSA-c2g3-c4gc-w5wgHigh
3mo ago

ReDoS in DotVVM routing

ReDoS in DotVVM routing

▾ TwilightDotVVM · DotVVMvia GHSA
CVE-2026-55470High· 7.5
3mo ago

HAPI FHIR: Incomplete fix for CVE-2026-45367: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS

HAPI FHIR: Incomplete fix for CVE-2026-45367: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS

▾ Twilightuhn · ca.uhn.hapi.fhir:org.hl7.fhir.dstu2EPSS 0.68%via GHSA
GHSA-g75f-g53v-794xMedium· 4.3
3mo ago

Bleach linkify(parse_email=True) CPU exhaustion via unbounded email regex scanning

Bleach linkify(parse_email=True) CPU exhaustion via unbounded email regex scanning

▾ Sunlitbleach · bleachvia GHSA
CVE-2026-54268High
3mo ago

@angular/common: Denial of Service (DoS) via OOM in Date Formatting (formatDate)

@angular/common: Denial of Service (DoS) via OOM in Date Formatting (formatDate)

▾ Twilightangular · @angular/commonEPSS 0.58%via GHSA
CVE-2026-48125Medium· 5.3
3mo ago

UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()`

UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()`

▾ Sunlitua-parser-js · ua-parser-jsEPSS 0.52%via GHSA
CVE-2026-44496High· 7.5PoC
3mo ago

Axios is a promise based HTTP client for the browser and Node.js

Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF cookie name without escaping regex metac…

▾ Midnightaxios · axiosEPSS 0.97%via NVD
CVE-2026-41848Low· 3.7
3mo ago

Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(St…

Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the following methods in AntPathMatcher: match(St…

▾ Sunlitvmware · spring_frameworkEPSS 0.40%via NVD
CVE-2026-10291Medium· 4.3
3mo ago

A security vulnerability has been detected in Enderfga claw-orchestrator up to 3.7.0

A security vulnerability has been detected in Enderfga claw-orchestrator up to 3.7.0. The impacted element is the function validateRegex of the file claw-orchestrator/src/embedded-server.ts of the component Session Grep Endpoint. The man…

▾ SunlitEPSS 0.35%via NVD
CVE-2026-33079High· 7.5
4mo ago

In versions 3.0.0a1 through 3.2.0 of Mistune, there is a ReDoS (Regular Expression Denial of Service) vulnerability in `LINK_TITLE_RE` that allows an attacker who can supply Markdown for parsing to cause denial of service

In versions 3.0.0a1 through 3.2.0 of Mistune, there is a ReDoS (Regular Expression Denial of Service) vulnerability in `LINK_TITLE_RE` that allows an attacker who can supply Markdown for parsing to cause denial of service. The regular ex…

▾ Twilightmistune · mistuneEPSS 0.70%via NVD
CVE-2026-0967Medium· 5.5
6mo ago

A flaw was found in libssh

A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could craft specific hostnames that when processed by the `match_pattern()` function can lead to inefficient regular expressio…

▾ Sunlitlibssh · libsshEPSS 0.22%via NVD
CVE-2026-4926High· 7.5
6mo ago

Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`

Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex grows exponentially with the number of groups, causing denial of servic…

▾ Twilightpillarjs · path-to-regexpEPSS 0.89%via NVD
CWE-1333 vulnerabilities (CVEs) — page 3 · VulnSea