CVE detail
CVE-2026-10692
A weakness has been identified in johnhuang316 code-index-mcp up to 2.14.0. Affected is the function is_safe_regex_pattern of the component search_code_advanced. Executing a manipulation of the argument regex can lead to inefficient regular expression complexity. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 2.14.1 is able to address this issue. This patch is called 25bc02fac74051ddae15ce79e952f00211b1ea6b. Upgrading the affected component is recommended.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 22.0 · diversity 6.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
8 source links · newest first
- https://vuldb.com/vuln/367961/ctivuldb.com
No excerpt available.
Exploitvuldb.comJun 3, 2026, 12:16 AM - https://vuldb.com/vuln/367961vuldb.com
No excerpt available.
Exploitvuldb.comJun 3, 2026, 12:16 AM - https://vuldb.com/submit/830786vuldb.com
No excerpt available.
Exploitvuldb.comJun 3, 2026, 12:16 AM - https://vuldb.com/cve/CVE-2026-10692vuldb.com
No excerpt available.
Exploitvuldb.comJun 3, 2026, 12:16 AM No excerpt available.
Exploitgithub.comJun 3, 2026, 12:16 AMNo excerpt available.
Exploitgithub.comJun 3, 2026, 12:16 AM- https://github.com/johnhuang316/code-index-mcp/commit/25bc02fac74051ddae15ce79e952f00211b1ea6bgithub.com
No excerpt available.
Exploitgithub.comJun 3, 2026, 12:16 AM No excerpt available.
Exploitgithub.comJun 3, 2026, 12:16 AM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-73556CVSS 5.3 · Medium
vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex parameter in vllm/v1/structured_output/backend_lm_format_enforcer.…
- CVE-2026-72912CVSS 4.3 · Medium
CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-recipe parser in src/core/Utils.mjs can exhaust client-side CP…
- CVE-2026-70489CVSS 6.5 · Medium
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automation recurrence parsing in backend/open_webui/utils/automation…
- CVE-2026-49485CVSS 7.5 · High
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.9 and 6.9.4.2, all implementations of FHIRPathEngine accept a…
- CVE-2026-49477CVSS 7.5 · High
Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to ca…
- CVE-2026-48125CVSS 5.3 · Medium
UAParser.js is a JavaScript library to detect browsers, operating systems, CPUs, and devices from user-agent data. From 2.0.1 until 2.0.10, a regular expression denial-of-service…