CWE-185: Incorrect Regular Expression
The product specifies a regular expression in a way that causes data to be improperly matched or compared.
29 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2024-52289 — authentik has an insecure default configuration for OAuth2 Redirect URIs
- CVE-2025-54365 — fastapi-guard patch contains bypassable RegEx
- CVE-2026-33418 — @dicebear/converter ensureSize() Vulnerable to SVG Dimension Capping Bypass via XML Comment Injection
- CVE-2025-20139 — A vulnerability in chat messaging features of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remo
- CVE-2026-25479 — Litestar has an AllowedHosts validation bypass due to unescaped regex metacharacters in configured host patterns
- CVE-2026-33347 — league/commonmark has an embed extension allowed_domains bypass
- CVE-2026-4296 — Incorrect Regular Expression vulnerability in GitHub Enterprise Server allowed unauthorized access to user accounts via OAuth callback URL validation bypass
- CVE-2026-56021 — Webmin information disclosure via regex pattern
- CVE-2026-48147 — Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker
- CVE-2026-25542 — Tekton Pipelines: VerificationPolicy regex pattern bypass via substring matching
- CVE-2026-3419 — Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation
- CVE-2026-24398 — Hono's IPv4 address validation bypass in IP Restriction Middleware allows IP spoofing
- CVE-2026-39350 — Istio AuthorizationPolicy Incorrect Regex Matching of Dots in serviceAccounts Fields Allows Policy Bypass
- CVE-2026-47674 — Hono: IP Restriction bypasses static deny rules for non-canonical IPv6
- CVE-2026-27895 — LAM has incorrect regular expression in PDF export component that allows user to upload files of any type
- CVE-2026-73425 — @astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped
- CVE-2026-45065 — Symfony: UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-Site //host URL Injection
- CVE-2026-64655 — GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacters in SAN Matching
Recently published
- CVE-2026-73425 — @astrojs/netlify generates an overly-broad Netlify Image CDN allowlist because remotePatterns.pathname metacharacters are not escaped
- CVE-2026-64655 — GitHub CLI: Attestation Verification Bypass via Unescaped Regex Metacharacters in SAN Matching
- CVE-2026-45065 — Symfony: UrlGenerator Route-Requirement Bypass via Unanchored Regex Alternation → Off-Site //host URL Injection
- CVE-2026-56021 — Webmin information disclosure via regex pattern
- CVE-2026-47674 — Hono: IP Restriction bypasses static deny rules for non-canonical IPv6
- CVE-2026-48147 — Budibase: Unanchored Regex in `matchers.ts` Allows CSRF Bypass via Query String Injection in Budibase Worker
- CVE-2026-4296 — Incorrect Regular Expression vulnerability in GitHub Enterprise Server allowed unauthorized access to user accounts via OAuth callback URL validation bypass
- CVE-2026-25542 — Tekton Pipelines: VerificationPolicy regex pattern bypass via substring matching
- CVE-2026-39350 — Istio AuthorizationPolicy Incorrect Regex Matching of Dots in serviceAccounts Fields Allows Policy Bypass
- CVE-2026-33347 — league/commonmark has an embed extension allowed_domains bypass
- CVE-2026-33418 — @dicebear/converter ensureSize() Vulnerable to SVG Dimension Capping Bypass via XML Comment Injection
- CVE-2026-27895 — LAM has incorrect regular expression in PDF export component that allows user to upload files of any type
- CVE-2026-3419 — Fastify's Missing End Anchor in "subtypeNameReg" Allows Malformed Content-Types to Pass Validation
- CVE-2026-25479 — Litestar has an AllowedHosts validation bypass due to unescaped regex metacharacters in configured host patterns
- CVE-2026-24398 — Hono's IPv4 address validation bypass in IP Restriction Middleware allows IP spoofing
- CVE-2025-54365 — fastapi-guard patch contains bypassable RegEx
- CVE-2025-20139 — A vulnerability in chat messaging features of Cisco Enterprise Chat and Email (ECE) could allow an unauthenticated, remo
- CVE-2024-52289 — authentik has an insecure default configuration for OAuth2 Redirect URIs