CVEs classified under CWE-407, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2026-94658: Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue affects Apache Thrift: before 0.25.0. Users are…
CVE-2026-103604: Inefficient algorithmic complexity in X.509 distinguished name string conversion (X509Name.ToString and IetfUtilities.ValueToString) in…
CVE-2026-49250: Conform, a type-safe form validation library, allows the parsing of nested objects in the form of object.property. From 1.8.0 until 1.19.4…
CVE-2026-83613: xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) DOMParser and XMLSerializer module. Prior to @xmldom/xmldom versions…
CVE-2026-54284: sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, TokenList construction and string conversion in sqlparse/sql.py…
CVE-2026-65623: Inefficient Algorithmic Complexity vulnerability in mtrudel bandit allows unauthenticated remote denial of service via CPU exhaustion…
CVE-2026-57480: Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.9.1-alpha.12 and 8.6.82…
CVE-2026-55206: py7zr is a Python-based library and utility to support 7zip archive compression, decompression, encryption and decryption. Prior to 1.1.3…
CVE-2026-58226: Inefficient Algorithmic Complexity vulnerability in elixir-mint hpax allows unauthenticated denial-of-service via unbounded HPACK integer…
CVE-2026-54892: Inefficient algorithmic complexity in Plug's nested-parameter decoder allows an unauthenticated remote attacker to cause denial of service…
CVE-2026-96287: Inefficient Algorithmic Complexity vulnerability in Apache Thrift Perl bindings. This issue affects Apache Thrift: before 0.25.0. Users are…
CVE-2026-94655: Allocation of resources without limits or throttling, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This…
CVE-2026-96292: Inefficient regular expression complexity, Inefficient Algorithmic Complexity vulnerability in Apache Thrift Lua bindings. This issue…
CVE-2026-94653: Inefficient Algorithmic Complexity vulnerability in Apache Thrift PHP bindings. This issue affects Apache Thrift: before 0.25.0. Users are…
CVE-2026-65634: Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENTIFIER decoder allows a remote unauthenticated attacker to cause…
CVE-2026-82760: Inefficient Algorithmic Complexity vulnerability in team-alembic AshAuthentication allows an unauthenticated attacker to exhaust CPU and…
CVE-2026-100700 — CVSS 7.5 (high): nodemailer before 10.0.6 contains a denial of service vulnerability in the addressparser free-text fallback regex pattern that exhibits…
CVE-2026-87081 — CVSS 7.5 (high): Net::IDN::UTS46 versions before 2.590 for Perl allow CPU exhaustion via quadratic punycode encoding of an overlong label before the length…
CVE-2026-87079 — CVSS 7.5 (high): Net::IDN::Punycode versions before 2.590 for Perl allow CPU exhaustion via quadratic insertion cost when decoding a long label in…
CVE-2026-71418 — CVSS 7.5 (high): Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.0 until…
CVE-2026-63447 — CVSS 7.5 (high): Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. From 8.0.5 until…
CVE-2026-69184 — CVSS 7.5 (high): c-ares is an asynchronous resolver library. Prior to 1.34.7, ares_dns_name_parse() enforces backward DNS compression pointers but does not…
CVE-2026-92987 — CVSS 7.5 (high): roxmltree through 0.21.1 performs quadratic-time attribute and namespace validation during XML parsing without limits on attribute count…
CVE-2026-90776 — CVSS 7.5 (high): Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time complexity vulnerability in the addressparser component when parsing…
CVE-2026-87822 — CVSS 7.5 (high): t-digest versions 3.1 through 3.3 fail to validate centroid means during deserialization in MergingDigest.fromBytes, allowing attackers to…
CVE-2024-58382 — CVSS 7.5 (high): league/commonmark versions before 2.6.0 contain polynomial time complexity vulnerabilities in Markdown parsing that allow attackers to…
CVE-2026-86435 — CVSS 7.5 (high): commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Footnote extension that fails to deduplicate…
CVE-2026-86434 — CVSS 7.5 (high): league/commonmark versions >= 2.0.0 and < 2.8.4 (patched in 2.9.0) contain a denial of service vulnerability in UniqueSlugNormalizer::normal…
CVE-2026-86433 — CVSS 7.5 (high): commonmark versions from 1.5.0 before 2.8.4 contain a denial of service vulnerability in the Attributes extension where…
CVE-2026-86430 — CVSS 7.5 (high): league/commonmark versions before 2.9.1 contain multiple denial of service vulnerabilities in fenced code block detection, reference link…
CVE-2026-86429 — CVSS 7.5 (high): The league/commonmark (thephpleague/commonmark) library in versions >= 1.5.0 and < 2.9.1 contains quadratic parsing complexity in its…
CVE-2026-86428 — CVSS 7.5 (high): commonmark versions from 1.5.0 before 2.10.0 contain a denial of service vulnerability in the AttributesExtension when processing…
CVE-2026-85446 — CVSS 7.5 (high): MOOS-IvP versions through 24.8.1 contain a quadratic processing vulnerability in uFldNodeComms where each new node identity creates a…
CVE-2026-49329 — CVSS 7.5 (high): A flaw was found in openshift/oauth-server. The OAuth login and error page endpoints pass the unauthenticated Accept-Language header to…
CVE-2026-81722 — CVSS 7.5 (high): nltk PorterStemmer in versions <= 3.10.2 (fixed in 3.10.3) contains an inefficient-algorithmic-complexity denial of service in…
CVE-2026-75005 — CVSS 7.5 (high): Inefficient Algorithmic Complexity vulnerability in Apache APISIX. A single small request can pin a gateway worker at 100% CPU for an…
CVE-2026-75596 — CVSS 7.5 (high): Netty is an asynchronous, event-driven network application framework. Prior to 4.1.137.Final and 4.2.17.Final, the default…
CVE-2026-66046 — CVSS 7.5 (high): Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in…
CVE-2026-73643 — CVSS 7.5 (high): js-yaml is a JavaScript YAML parser and dumper. From 5.0.0 until 5.2.2, parsing a small YAML document can take exponential time when an…
CVE-2026-70453 — CVSS 7.5 (high): rsync before 3.5.0 contains an algorithmic complexity vulnerability in the hash_search() function that allows a remote attacker to cause a…
CVE-2026-71488 — CVSS 7.5 (high): league/commonmark is a PHP library for parsing and rendering CommonMark Markdown. From 0.6.0 until 2.9.0, specially crafted Markdown lines…
CVE-2026-68750 — CVSS 7.5 (high): Inefficient Algorithmic Complexity vulnerability in the traversal engine in rrrene html_sanitize_ex allows an unauthenticated remote…
CVE-2026-71321 — CVSS 7.5 (high): Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, the internal island renderer endpoint…
CVE-2026-58059 — CVSS 7.5 (high): In Bouncy Castle for Java before 1.85, Quadratic-time escaping when stringifying X.500 distinguished names. This issue also affects Bouncy…
CVE-2026-55968 — CVSS 7.5 (high): Inefficient Algorithmic Complexity, Allocation of Resources Without Limits or Throttling vulnerability in Apache Thrift Node.js bindings…
CVE-2026-56669 — CVSS 7.5 (high): Elysia is a Typescript framework for request validation, type inference, OpenAPI documentation, and client-server communication. Prior to…
CVE-2026-59928 — CVSS 7.5 (high): Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repeated or distinct…
CVE-2026-59925 — CVSS 7.5 (high): Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-asterisk or…
CVE-2026-59922 — CVSS 7.5 (high): Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs…