CWE-1333: Inefficient Regular Expression Complexity
The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.
350 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-25547 — @isaacs/brace-expansion has Uncontrolled Resource Consumption
- CVE-2025-25200 — Koa has Inefficient Regular Expression Complexity
- CVE-2026-26996 — minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern
- CVE-2025-6998 — Calibre Web 0.6.24 & Autocaliweb 0.7.0 - ReDoS
- CVE-2025-58451 — Cattown Vulnerable to Inefficient Regular Expression Complexity and Uncontrolled Resource Consumption
- CVE-2026-30925 — Parse Server affected by Regular Expression Denial of Service (ReDoS) via `$regex` query in LiveQuery
- CVE-2026-52778 — YesWiki has Unsafe eval() in Formula Calculator - Remote Code Execution (RCE) & Denial of Service (DoS)
- CVE-2025-62484 — Zoom Workplace Clients - Inefficient Regular Expression Complexity
- CVE-2024-52798 — path-to-regexp Unpatched `path-to-regexp` ReDoS in 0.1.x
- CVE-2026-4867 — path-to-regexp vulnerable to Regular Expression Denial of Service via multiple route parameters
- CVE-2026-33671 — Picomatch has a ReDoS vulnerability via extglob quantifiers
- CVE-2026-30837 — Elysia has a string URL format redos
- CVE-2026-23897 — Apollo Server is vulnerable to denial of service with `startStandaloneServer`
- CVE-2026-21868 — Flag Forge has ReDoS Vulnerability in User Profile Lookup API
- CVE-2025-68475 — Fedify has ReDoS Vulnerability in HTML Parsing Regex
- CVE-2025-66020 — Valibot has a ReDoS vulnerability in `EMOJI_REGEX`
- CVE-2025-54796 — Copyparty is vulnerable to Regex Denial of Service (ReDoS) attacks through "Recent Uploads" page
- CVE-2025-33090 — IBM Concert Software denial of service
- CVE-2025-25283 — parse-duraton vulnerable to Regex Denial of Service that results in event loop delay and out of memory
- CVE-2024-5552 — ReDoS in kubeflow/kubeflow
Recently published
- CVE-2026-75880 — Apache Artemis, Apache ActiveMQ Artemis: Message selector wildcard handling could lead to denial of service
- CVE-2026-87819 — GitPython before 3.1.60 Denial of Service via ReDoS
- CVE-2026-86081 — n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
- CVE-2026-85062 — Colord: Slow rejection of oversized malformed color strings
- CVE-2026-83619 — xmldom: End-tag Whitespace-Trim Regex ReDoS — quadratic backtracking in the 0.8.x end-tag parser
- CVE-2026-83606 — xmldom PI grammar regex ReDoS: quadratic backtracking on unterminated processing instructions
- CVE-2024-58379 — nodemailer before 6.9.9 ReDoS via attachDataUrls parameter
- CVE-2026-55520 — Protego: Exponential backtracking ReDoS in robots.txt URL wildcard matching
- CVE-2026-80206 — NLTK 3.10.2 Regular Expression Denial of Service via tgrep
- CVE-2026-80205 — NLTK before 3.10.0 ReDoS via Text.findall() unvalidated regex
- CVE-2026-79770 — Nokogiri before 1.19.3 ReDoS via CSS selector tokenizer
- CVE-2026-66766 — Denial of Service (DoS) in SAP S/4HANA (Manage Supply Protection)
- CVE-2026-70656 — Checkmate: Regular Expression Denial of Service (ReDoS) via User-Controlled Regex in Monitor Advanced Matching
- CVE-2026-72818 — NLTK TweetTokenizer URL Pattern Backtracks Catastrophically on Naked-Domain-Like Input
- CVE-2026-77082 — n8n before 1.123.69 ReDoS via Filter and Switch Node
- CVE-2026-62317 — Logto: ReDoS via unescaped user input in email subaddressing regex (blockSubaddressing)
- CVE-2026-62672 — Grav: Authenticated ReDoS via regex_replace in Twig Sandbox
- CVE-2026-74039 — Wazuh 4.0.0 < 4.14.7 API DoS via Deeply Nested JSON auth_context
- CVE-2026-54284 — sqlparse: TokenList.__init__ materializes O(subtree) value per group, causing CPU DoS before depth/token caps trigger
- CVE-2026-59893 — sqlparse: Inefficient Regex Handling of Dollar-Quoted SQL Literals Leads to ReDoS (Denial of Service)