CWE-624: Executable Regular Expression Error
The product uses a regular expression that either (1) contains an executable component with user-controlled inputs, or (2) allows a user to enable execution by inserting pattern modifiers.
2 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-25237 — PEAR is Vulnerable to PHP Code Execution via preg_replace /e in Bug Update Emails
- CVE-2024-41655 — TF2 Item Format Regular Expression Denial of Service vulnerability
Recently published
- CVE-2026-25237 — PEAR is Vulnerable to PHP Code Execution via preg_replace /e in Bug Update Emails
- CVE-2024-41655 — TF2 Item Format Regular Expression Denial of Service vulnerability