Semgrep is a static analysis and code-scanning tool distributed as both open-source and commercial offerings, with its vulnerability exposure centered on the core scanning engine product. The observed weakness class reflects the computational cost of complex pattern matching and regular expression evaluation inherent to code analysis at scale, a characteristic concern in tools that parse and search arbitrary source code.
The number and severity of CVEs published that impact products developed by Semgrep over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-32758HIGH giturlparse (aka git-url-parse) through 1.2.2, as used in Semgrep 1.5.2 through 1.24.1, is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing untrusted URLs. Thi | May 15, 2023 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Semgrep.
Media articles that mention a CVE ID that affects a product developed by Semgrep — matched by CVE ID, not by vendor name.