The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.
Volume of CVEs assigned to CWE-1333 and their average CVSS base score over time.
Top CVEs that have been assigned this CWE. A single CVE can have multiple CWE assignments, though many have just one.
455 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-8124HIGH An issue was discovered in GitLab CE/EE affecting all versions starting from 16.4 prior to 17.1.7, starting from 17.2 prior to 17.2.5, starting from 17.3 prior to 17.3.2 which cou | Sep 12, 2024 | 7.5 | 43 | NO | NO |
CVE-2023-3364HIGH An issue has been discovered in GitLab CE/EE affecting all versions starting from 8.14 before 16.0.8, all versions starting from 16.1 before 16.1.3, all versions starting from 16.2 | Aug 2, 2023 | 7.5 | 42 | NO | NO |
CVE-2026-52778CRITICAL YesWiki is a wiki system written in PHP. Prior to version 4.6.6, an unsafe execution vulnerability exists in the Bazar form field calculator (CalcField.php) of YesWiki. The applica | Jun 8, 2026 | 9.8 | 41 | NO | NO |
CVE-2024-25126HIGH Rack is a modular Ruby web server interface. Carefully crafted content type headers can cause Rack’s media type parser to take much longer than expected, leading to a possible deni | Feb 29, 2024 | 7.5 | 40 | NO | NO |
CVE-2024-2651MEDIUM An issue has been discovered in GitLab CE/EE affecting all versions before 16.9.7, all versions starting from 16.10 before 16.10.5, all versions starting from 16.11 before 16.11.2. | May 14, 2024 | 6.5 | 39 | NO | NO |
CVE-2021-32837HIGH mechanize, a library for automatically interacting with HTTP web servers, contains a regular expression that is vulnerable to regular expression denial of service (ReDoS) prior to | Jan 17, 2023 | 7.5 | 39 | NO | NO |
CVE-2026-48801HIGH linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package's primary public API, has O(N²) algorithmic complexity f | Jul 14, 2026 | 8.7 | 37 | NO | NO |
CVE-2026-57584HIGH Phalcon is a high-performance, full-stack PHP framework. Prior to 5.15.0, every Phalcon MVC application built with a default router registers a built-in route whose compiled PCRE p | Jul 10, 2026 | 8.7 | 36 | NO | NO |
CVE-2026-49485HIGH HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.9 and 6.9.4.2, all implementations of FHIRPathEngine accept ar | Jul 17, 2026 | 7.5 | 35 | NO | NO |
CVE-2026-52746HIGH JSONata is a JSON query and transformation language. Prior to 2.2.0, malicious non-matching inputs to the $toMillis function can cause superlinear backtracking in the ISO-8601 vali | Jul 17, 2026 | 7.5 | 35 | NO | NO |
Exploit activity across CVEs assigned to this CWE, including CVEs that carry other CWE assignments.
Social posts that mention CVE IDs assigned to this CWE. This is assigned-CVE activity, not mentions of the CWE label itself.
Media articles that mention CVE IDs assigned to this CWE. This is assigned-CVE coverage, not mentions of the CWE label itself.