Skip to main content

CWE archive

CWE-1333 CVEs

Programmatic archive

455 CVEs tagged with CWE-13335 Critical, 217 High, 195 Medium, 37 Low, 1 Unrated.

CVE-2026-16270

Published Jul 22, 2026

Open Mercato does not validate regex rules. An attacker with privileges to create the regex rule can add an unsafe regex to a field. When someone provide the proper string it can…

CVSS 6.9 · Medium
evidence mentions
3
Buzz score
28.9

CVE-2026-49485

Published Jul 17, 2026

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.9 and 6.9.4.2, all implementations of FHIRPathEngine accept a…

CVSS 7.5 · High
evidence mentions
6
Buzz score
24.5

CVE-2026-52746

Published Jul 17, 2026

JSONata is a JSON query and transformation language. Prior to 2.2.0, malicious non-matching inputs to the $toMillis function can cause superlinear backtracking in the ISO-8601 val…

CVSS 7.5 · High
evidence mentions
6
Buzz score
24.5

CVE-2026-14741

Published Jul 17, 2026

HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date. parse_date() matches the date string against a chain of alternative…

CVSS 7.5 · High
evidence mentions
4
Buzz score
27.6

CVE-2026-62237

Published Jul 17, 2026

Grav before 2.0.4 contains a regular expression denial of service (ReDoS) vulnerability in the regex_replace filter and function, which are allowlisted in the Twig content sandbox…

CVSS 6.0 · Medium
evidence mentions
2
Buzz score
17.5

CVE-2026-45367

Published Jul 16, 2026

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.7, the FHIRPathEngine implementation passes user-controlled r…

CVSS 7.5 · High
evidence mentions
6
Buzz score
24.5

CVE-2026-49477

Published Jul 14, 2026

Soup Sieve is a CSS selector library designed to be used with Beautiful Soup 4. Prior to 2.8.4, the CSS selector parser in soupsieve contains a regular expression vulnerable to ca…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-48801

Published Jul 14, 2026

linkify-it is a links recognition library with full Unicode support. Prior to 5.0.1, LinkifyIt.prototype.match, the package's primary public API, has O(N²) algorithmic complexity…

CVSS 8.7 · High
evidence mentions
2
Buzz score
16.0

CVE-2026-48125

Published Jul 14, 2026

UAParser.js is a JavaScript library to detect browsers, operating systems, CPUs, and devices from user-agent data. From 2.0.1 until 2.0.10, a regular expression denial-of-service…

CVSS 5.3 · Medium
evidence mentions
3
Buzz score
18.9

CVE-2026-45305

Published Jul 14, 2026

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, Symfony\Component\Yaml\Parser::clean…

CVSS 8.7 · High
evidence mentions
7
Buzz score
30.8
Vendor/product tagsBeta · best-effort

CVE-2026-45133

Published Jul 14, 2026

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. Prior to 5.4.52, 6.4.40, 7.4.12, and 8.0.12, when the parser is exposed to attack…

CVSS 8.2 · High
evidence mentions
6
Buzz score
29.5
Vendor/product tagsBeta · best-effort

CVE-2026-45756

Published Jul 14, 2026

Symfony is a PHP framework for web and console applications and a set of reusable PHP components. From 7.3.0-BETA1 until 7.4.12 and 8.0.12, the JsonPath component compiles attacke…

CVSS 8.2 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-6850

Published Jul 13, 2026

Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of message attachment field values, which allows an authenticat…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-57584

Published Jul 10, 2026

Phalcon is a high-performance, full-stack PHP framework. Prior to 5.15.0, every Phalcon MVC application built with a default router registers a built-in route whose compiled PCRE…

CVSS 8.7 · High
evidence mentions
4
Buzz score
21.1

CVE-2026-59220

Published Jul 9, 2026

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.2 before 0.10.0, the SKILL_MENTION_RE and strip_re regular expressions in backend/op…

CVSS 6.5 · Medium
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-55470

Published Jul 8, 2026

HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.10, the fix for CVE-2026-45367 incompletely patched the DSTU2…

CVSS 7.5 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-15154

Published Jul 8, 2026

A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Expression Denial of Service (ReDoS), allows a remote attacke…

CVSS 6.5 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2026-59928

Published Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a Markdown document containing many repeated or distinct reference-link definitions causes quadrati…

CVSS 7.5 · High
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-59925

Published Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, long sequences of well-formed double-asterisk or triple-asterisk emphasis pairs around a character…

CVSS 7.5 · High
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-59922

Published Jul 8, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, a run of closed tilde, equals-sign, or caret marker pairs around a character causes quadratic work…

CVSS 7.5 · High
evidence mentions
4
Buzz score
26.1
Vendor/product tagsBeta · best-effort

CVE-2026-14895

Published Jul 7, 2026

String::Util versions before 1.36 for Perl are susceptible to a regular expression denial of service. The trim and rtrim functions stripped trailing whitespace with s/\s*$//u. Be…

CVSS 7.5 · High
evidence mentions
4
Buzz score
27.6

CVE-2026-55574

Published Jul 6, 2026

vLLM is a high-throughput and memory-efficient inference and serving engine for LLMs. Prior to 0.24.0, the structured_outputs.regex API parameter passes a user-supplied regular ex…

CVSS 8.7 · High
evidence mentions
3
Buzz score
18.9
Vendor/product tagsBeta · best-effort

CVE-2026-58578

Published Jul 2, 2026

LobeChat before version 2.2.10-canary.15 contains a regular expression denial of service (ReDoS) vulnerability that allows authenticated attackers to block the Node.js event loop…

CVSS 7.1 · High
evidence mentions
5
Buzz score
24.4

CVE-2026-52794

Published Jun 24, 2026

Sentry is an error tracking and performance monitoring tool. From 24.4.0 until 26.5.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Sentry's event ingest…

CVSS 7.5 · High
evidence mentions
2
Buzz score
16.0
Vendor/product tagsBeta · best-effort

CVE-2026-49851

Published Jun 24, 2026

Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.3.0, Mistune is vulnerable to a CPU exhaustion DoS due to superlinear (approximately O(n²)) behavior in…

CVSS 8.7 · High
evidence mentions
4
Buzz score
29.1
Showing 1-25 of 455 CVEsPage 1 of 19