VulnSea

CWE-1333

CVEs classified under CWE-1333, newest first.

101 CVEsRSS

CVE-2026-28356High· 7.5
6mo ago

multipart is a fast multipart/form-data parser for python

multipart is a fast multipart/form-data parser for python. Prior to 1.2.2, 1.3.1 and 1.4.0-dev, the parse_options_header() function in multipart.py uses a regular expression with an ambiguous alternation, which can cause exponential back…

▾ Twilightmultipart · multipartEPSS 1.0%via NVD
CVE-2025-10990High· 7.5
7mo ago

A flaw was found in REXML

A flaw was found in REXML. A remote attacker could exploit inefficient regular expression (regex) parsing when processing hex numeric character references (&#x...;) in XML documents. This could lead to a Regular Expression Denial of Serv…

▾ TwilightEPSS 0.49%via NVD
CVE-2025-69873Low· 2.9PoC
7mo ago

ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled

ajv (Another JSON Schema Validator) before 8.18.0 is vulnerable to Regular Expression Denial of Service (ReDoS) when the $data option is enabled. The pattern keyword accepts runtime data via JSON Pointer syntax ($data reference), which i…

▾ Twilightajv.js · ajvEPSS 0.50%via NVD
CVE-2026-24001High· 7.5
8mo ago

jsdiff is a JavaScript text differencing implementation

jsdiff is a JavaScript text differencing implementation. Prior to versions 8.0.3, 5.2.2, 4.0.4, and 3.5.1, attempting to parse a patch whose filename headers contain the line break characters `\r`, `\u2028`, or `\u2029` can cause the `pa…

▾ Twilightkpdecker · jsdiffEPSS 0.63%via NVD
CVE-2026-0621High· 7.5
8mo ago

Anthropic's MCP TypeScript SDK versions up to and including 1.25.1 contain a regular expression denial of service (ReDoS) vulnerability in the UriTemplate class when processing RFC 6570 exploded array patterns

Anthropic's MCP TypeScript SDK versions up to and including 1.25.1 contain a regular expression denial of service (ReDoS) vulnerability in the UriTemplate class when processing RFC 6570 exploded array patterns. The dynamically generated …

▾ Twilightlfprojects · mcp_typescript_sdkEPSS 0.45%via NVD
CVE-2025-6069Medium· 4.3
1y ago

The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.

The html.parser.HTMLParser class had worse-case quadratic complexity when processing certain crafted malformed inputs potentially leading to amplified denial-of-service.

▾ SunlitEPSS 0.59%via NVD
CVE-2024-10270Medium· 6.5
1y ago

A vulnerability was found in the Keycloak-services package

A vulnerability was found in the Keycloak-services package. If untrusted data is passed to the SearchQueryUtils method, it could lead to a denial of service (DoS) scenario by exhausting system resources due to a Regex complexity.

▾ SunlitRed Hat · keycloakEPSS 1.3%via NVD
CVE-2024-21539High· 7.5
1y ago

Versions of the package @eslint/plugin-kit before 0.2.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization

Versions of the package @eslint/plugin-kit before 0.2.3 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program by exploiting this vu…

▾ TwilightEPSS 0.50%via NVD
CVE-2024-21538High· 7.5
1y ago

Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization

Versions of the package cross-spawn before 6.0.6, from 7.0.0 and before 7.0.5 are vulnerable to Regular Expression Denial of Service (ReDoS) due to improper input sanitization. An attacker can increase the CPU usage and crash the program…

▾ TwilightEPSS 0.87%via NVD
CVE-2023-7279Low· 2.6
2y ago

A vulnerability has been found in Secure Systems Engineering Connaisseur up to 3.3.0 and classified as problematic

A vulnerability has been found in Secure Systems Engineering Connaisseur up to 3.3.0 and classified as problematic. This vulnerability affects unknown code of the file connaisseur/res/targets_schema.json of the component Delegation Name …

▾ Sunlitsecuresystems · connaisseurEPSS 0.54%via NVD
CVE-2024-21490High· 7.5PoC
2y ago

This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0

This affects versions of the package angular from 1.3.0; versions of the package angularjs from 1.3.0. A regular expression used to split the value of the ng-srcset directive is vulnerable to super-linear runtime due to backtracking. Wit…

▾ Midnightangularjs · angular.jsEPSS 1.9%via NVD
CWE-1333 vulnerabilities (CVEs) — page 4 · VulnSea