Skip to main content

CWE archive

CWE-1333 CVEs

Programmatic archive

468 CVEs tagged with CWE-13335 Critical, 223 High, 202 Medium, 37 Low, 1 Unrated.

CVE-2025-68475

Published Dec 22, 2025

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.6.13, 1.7.14, 1.8.15, and 1.9.2, a Regular Expression Denial of Servi…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2025-68142

Published Dec 16, 2025

PyMdown Extensions is a set of extensions for the `Python-Markdown` markdown project. Versions prior to 10.16.1 have a ReDOS bug found within the figure caption extension (`pymdow…

CVSS 2.7 · Low
Vendor/product tagsBeta · best-effort

CVE-2025-66020

Published Nov 26, 2025

Valibot helps validate data using a schema. In versions from 0.31.0 to 1.1.0, the EMOJI_REGEX used in the emoji action is vulnerable to a Regular Expression Denial of Service (ReD…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0

CVE-2025-61581

Published Oct 16, 2025

** UNSUPPORTED WHEN ASSIGNED ** Inefficient Regular Expression Complexity vulnerability in Apache Traffic Control. This issue affects Apache Traffic Control: all versions. Peopl…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-61921

Published Oct 10, 2025

Sinatra is a domain-specific language for creating web applications in Ruby. In versions prior to 4.2.0, there is a denial of service vulnerability in the `If-Match` and `If-None-…

CVSS 2.7 · Low
evidence mentions
5
Buzz score
32.4
Public PoC observed
Vendor/product tagsBeta · best-effort

CVE-2025-6051

Published Sep 14, 2025

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically within the `normalize_numbers()` method of the `…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-6638

Published Sep 12, 2025

A Regular Expression Denial of Service (ReDoS) vulnerability was discovered in the Hugging Face Transformers library, specifically affecting the MarianTokenizer's `remove_language…

CVSS 7.5 · High
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-58451

Published Sep 8, 2025

Cattown is a JavaScript markdown parser. Versions prior to 1.0.2 used regular expressions with inefficient, potentially exponential worst-case complexity. This could cause excessi…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0

CVE-2025-9670

Published Aug 29, 2025

A security flaw has been discovered in mixmark-io turndown up to 7.2.1. This affects an unknown function of the file src/commonmark-rules.js. Performing manipulation results in in…

CVSS 5.5 · Medium

CVE-2025-9308

Published Aug 21, 2025

A vulnerability has been found in yarnpkg Yarn up to 1.22.22. This impacts the function setOptions of the file src/util/request-manager.js. Such manipulation leads to inefficient…

CVSS 4.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-54364

Published Aug 20, 2025

Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. option_descriptions employs an inefficient regular expression pattern…

CVSS 6.9 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2025-54363

Published Aug 20, 2025

Microsoft Knack 0.12.0 allows Regular expression Denial of Service (ReDoS) in the knack.introspection module. extract_full_summary_from_signature employs an inefficient regular ex…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
20.4

CVE-2025-4690

Published Aug 19, 2025

A regular expression used by AngularJS'  linky https://docs.angularjs.org/api/ngSanitize/filter/linky  filter to detect URLs in input text is vulnerable to super-linear runtime du…

CVSS 4.3 · Medium
evidence mentions
2
Buzz score
21.0

CVE-2025-33090

Published Aug 18, 2025

IBM Concert Software 1.0.0 through 1.1.0 could allow a remote attacker to cause a denial of service using a specially crafted regular expression that would cause excessive resourc…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-2937

Published Aug 13, 2025

An issue has been discovered in GitLab CE/EE affecting all versions from 13.2 before 18.0.6, 18.1 before 18.1.4, and 18.2 before 18.2.2 that could have allowed authenticated users…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-55152

Published Aug 9, 2025

oak is a middleware framework for Deno's native HTTP server, Deno Deploy, Node.js 16.5 and later, Cloudflare Workers and Bun. In versions 17.1.5 and below, it's possible to signif…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
16.0

CVE-2025-5197

Published Aug 6, 2025

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the Hugging Face Transformers library, specifically in the `convert_tf_weight_name_to_pt_weight_name()` func…

CVSS 5.3 · Medium
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2025-54796

Published Aug 2, 2025

Copyparty is a portable file server. Versions prior to 1.18.9, the filter parameter for the "Recent Uploads" page allows arbitrary RegExes. If this feature is enabled (which is th…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-8262

Published Jul 28, 2025

A vulnerability was found in yarnpkg Yarn up to 1.22.22. It has been classified as problematic. Affected is the function explodeHostedGitFragment of the file src/resolvers/exotics…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2025-6998

Published Jul 24, 2025

ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denial of service via specially craft…

CVSS 8.7 · High

CVE-2025-54365

Published Jul 23, 2025

fastapi-guard is a security library for FastAPI that provides middleware to control IPs, log requests, detect penetration attempts and more. In version 3.0.1, the regular expressi…

CVSS 7.8 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2025-7579

Published Jul 14, 2025

A vulnerability was found in chinese-poetry 0.1. It has been rated as problematic. This issue affects some unknown processing of the file rank/server.js. The manipulation leads to…

CVSS 2.1 · Low
Showing 101-125 of 468 CVEsPage 5 of 19