CVEs classified under CWE-1333, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2026-82617 — CVSS 9.8 (critical): The two built-in name-finder patterns exposed by opennlp.tools.namefind.RegexNameFinderFactory - DEFAULT_REGEX_NAME_FINDER.EMAIL and…
CVE-2026-35458 — CVSS 9.8 (critical): Gotenberg is an API for converting document formats. In 8.29.1 and earlier, Gotenberg uses dlclark/regexp2 to compile user-supplied scope…
CVE-2023-29486 — CVSS 9.8 (critical): An issue was discovered in Heimdal Thor agent versions 3.4.2 and before 3.7.0 on Windows, allows attackers to bypass USB access…
CVE-2026-25547: @isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of brace-expansion. Prior to version 5.0.1, @isaacs/brace-expansion is…
CVE-2023-29487 — CVSS 9.1 (critical): An issue was discovered in Heimdal Thor agent versions 3.4.2 and before on Windows and 2.6.9 and before on macOS, allows attackers to cause…
CVE-2026-106104: Quasar Framework is a framework for building high-performance Vue.js user interfaces. Prior to 2.23.3, Platform.parseSSR() passed an…
CVE-2026-71190: In OpenStack Swift through 2.38.0, the proxy server Accept header parser contains a regular expression vulnerable to catastrophic…
CVE-2026-57584: Phalcon is a high-performance, full-stack PHP framework. Prior to 5.15.0, every Phalcon MVC application built with a default router…
CVE-2026-47138: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.77 and…
CVE-2025-6998: ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to…
CVE-2020-26310: Validate.js provides a declarative way of validating javascript objects. All versions as of 30 November 2020 contain one or more regular…
CVE-2020-26309: Validate.js provides a declarative way of validating javascript objects. Versions 0.11.3 and prior contain one or more regular expressions…
CVE-2020-26307: HTML2Markdown is a Javascript implementation for converting HTML to Markdown text. All available versions contain one or more regular…
CVE-2020-26306: Knwl.js is a Javascript library that parses through text for dates, times, phone numbers, emails, places, and more. Versions 1.0.2 and…
CVE-2023-23925 — CVSS 8.6 (high): Switcher Client is a JavaScript SDK to work with Switcher API which is cloud-based Feature Flag. Unsanitized input flows into Strategy…
CVE-2023-23621 — CVSS 8.6 (high): Discourse is an open-source discussion platform. Prior to version 3.0.1 on the `stable` branch and version 3.1.0.beta2 on the `beta` and…
CVE-2026-102990: basic-ftp is an FTP client for Node.js. Prior to 6.2.1, Client.list() can be forced by a malicious or compromised FTP server to spend…
CVE-2026-101903: Axios is a promise-based HTTP client for the browser and Node.js. From 1.16.1 until 1.20.0, the RFC 2397 regular expression allows slash…
CVE-2026-57577: DotVVM is an open source MVVM framework for web applications. Prior to 4.2.11, 4.3.15, and 5.0.0-preview09-final, a route containing…
CVE-2025-62484 — CVSS 8.1 (high): Inefficient regular expression complexity in certain Zoom Workplace Clients before version 6.5.10 may allow an unauthenticated user to…
CVE-2024-52798: path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be…
CVE-2026-105219 — CVSS 7.5 (high): Mammoth.js 1.3.0 before 1.12.3 contains a regular expression denial of service vulnerability in the style map tokeniser in…
CVE-2026-67989 — CVSS 7.5 (high): crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition…
CVE-2026-103043 — CVSS 7.5 (high): anchorme through 3.0.8 contains a regular expression denial of service vulnerability in the IPv6 host extraction regex due to catastrophic…
CVE-2026-77423 — CVSS 7.5 (high): JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in less viewer passes…
CVE-2026-77422 — CVSS 7.5 (high): JLine is a Java library for handling console input. From 3.0.0 until 3.30.15 and 4.3.1, the JLine built-in grep command in…
CVE-2026-93761 — CVSS 7.5 (high): An inefficient regular expression complexity issue in the in-memory query evaluation component of the Mongoid library may allow an…
CVE-2026-63460 — CVSS 7.5 (high): Vendure is an open-source headless commerce platform. Prior to 3.6.5, the public Shop GraphQL API allows an unauthenticated caller to…
CVE-2026-92599 — CVSS 7.5 (high): joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable to regular expression denial of service in…
CVE-2026-87819 — CVSS 7.5 (high): GitPython before 3.1.60 contains a regular expression denial of service vulnerability in Actor.name_email_regex that processes commit…
CVE-2026-84642 — CVSS 7.5 (high): The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression without escaping. For some…
CVE-2026-80205 — CVSS 7.5 (high): NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.findall() and TokenSearcher.findall()…
CVE-2026-79770 — CVSS 7.5 (high): Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokenizer affecting…
CVE-2026-66766 — CVSS 7.5 (high): SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vulnerability. An…
CVE-2026-72818 — CVSS 7.5 (high): The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokenizer.tokenize…
CVE-2026-62317 — CVSS 7.5 (high): Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's email subaddressing blocklist in…
CVE-2026-59893 — CVSS 7.5 (high): sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/keywords.py and the per-position loop in…
CVE-2026-67991 — CVSS 7.5 (high): crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-of-service condition…
CVE-2026-67422 — CVSS 7.5 (high): pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0, four inline…
CVE-2026-68749 — CVSS 7.5 (high): Inefficient Regular Expression Complexity vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthenticated remote…
CVE-2026-60075 — CVSS 7.5 (high): Date::Manip versions through 7.00 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substitution in…
CVE-2026-52746 — CVSS 7.5 (high): JSONata is a JSON query and transformation language. Prior to 2.2.0 and 1.8.9, malicious non-matching inputs to the $toMillis function can…
CVE-2026-14741 — CVSS 7.5 (high): HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date. parse_date() matches the…
CVE-2026-45367 — CVSS 7.5 (high): HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.7, the FHIRPathEngine…
CVE-2026-48801 — CVSS 7.5 (high): linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package's primary…
CVE-2026-45305 — CVSS 7.5 (high): Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and…
CVE-2026-55470 — CVSS 7.5 (high): HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, the fix for…
CVE-2026-14895 — CVSS 7.5 (high): String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. The trim and rtrim functions stripped…
CVE-2026-55574 — CVSS 7.5 (high): vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the structured_outputs.regex API…