CWE-1333: CWE-1333

98
Total CVEs
1
Critical
66
High
6.9
Avg CVSS

Yearly Trend

2026
8
2025
30
2024
27
2023
14
2022
10

Top Affected Vendors

1 Gitlab 12
2 Fedoraproject 5
3 Lunary 4
4 Huggingface 4
5 Apache 4
6 Angularjs 3
7 Ruby Lang 3
8 Ibm 2
9 Opensuse 1
10 Promptworks 1

All CWE-1333 CVEs (98)

CVE-2023-29487
9.1

This CVE describes a denial-of-service vulnerability in Heimdal Thor agent's Threat To Process Correlation module. Attackers can exploit this to cause...

Dec 21, 2023
CVE-2025-62484
8.1

A regular expression complexity vulnerability in Zoom Workplace Clients allows unauthenticated attackers to potentially escalate privileges via networ...

Nov 13, 2025
CVE-2026-23897
7.5

Apollo Server's startStandaloneServer function is vulnerable to denial-of-service attacks when attackers send GraphQL requests with specially crafted ...

Feb 4, 2026
CVE-2026-23956
7.5

seroval library versions 1.4.0 and below contain vulnerabilities in RegExp serialization that can cause memory exhaustion or ReDoS (Regular Expression...

Jan 22, 2026
CVE-2026-0621
7.5

This CVE describes a regular expression denial of service (ReDoS) vulnerability in Anthropic's MCP TypeScript SDK. Attackers can exploit this by sendi...

Jan 5, 2026
CVE-2025-68475
7.5

This CVE describes a Regular Expression Denial of Service (ReDoS) vulnerability in Fedify's document loader. Attackers can cause catastrophic backtrac...

Dec 22, 2025
CVE-2025-66020
7.5

This CVE describes a Regular Expression Denial of Service (ReDoS) vulnerability in Valibot's emoji validation regex. Attackers can submit a short mali...

Nov 26, 2025
CVE-2025-61581
7.5

This CVE describes an Inefficient Regular Expression Complexity (ReDoS) vulnerability in Apache Traffic Control's Traffic Router management interface....

Oct 16, 2025
CVE-2025-33090
7.5

CVE-2025-33090 is a denial-of-service vulnerability in IBM Concert Software where a remote attacker can send specially crafted regular expressions tha...

Aug 18, 2025
CVE-2025-53539
7.5

CVE-2025-53539 is a denial-of-service vulnerability in FastAPI Guard's penetration detection system where inefficient regex patterns can cause polynom...

Jul 7, 2025
CVE-2025-3262
7.5

A Regular Expression Denial of Service (ReDoS) vulnerability in huggingface/transformers allows attackers to degrade application performance or cause ...

Jul 7, 2025
CVE-2024-8998
7.5

A Regular Expression Denial of Service (ReDoS) vulnerability in lunary-ai/lunary allows attackers to submit specially crafted inputs that cause the se...

Mar 20, 2025
CVE-2024-8763
7.5

A Regular Expression Denial of Service (ReDoS) vulnerability in lunary-ai/lunary allows attackers to cause indefinite server hangs by sending speciall...

Mar 20, 2025
CVE-2024-8764
7.5

This vulnerability in lunary-ai/lunary allows authenticated users to upload and execute arbitrary regular expressions on the server, potentially causi...

Mar 20, 2025
CVE-2024-12720
7.5

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the huggingface/transformers library's tokenization_nougat_fast.py file. The po...

Mar 20, 2025
CVE-2025-25283
7.5

The parse-duration library versions before 2.1.3 are vulnerable to denial of service attacks through CPU-bound operations and memory exhaustion. Attac...

Feb 12, 2025
CVE-2025-25200
7.5

Koa middleware for Node.js versions prior to 0.21.2, 1.7.1, 2.15.4, and 3.0.0-alpha.3 contain a regular expression denial-of-service (ReDoS) vulnerabi...

Feb 12, 2025
CVE-2024-46242
7.5

This vulnerability allows attackers to cause a denial of service (DoS) by submitting specially crafted email addresses during user registration in CTF...

Jan 7, 2025
CVE-2024-41766
7.5

This vulnerability in IBM Engineering Lifecycle Optimization - Publishing allows remote attackers to cause denial of service by sending specially craf...

Jan 4, 2025
CVE-2024-21539
7.5

CVE-2024-21539 is a Regular Expression Denial of Service (ReDoS) vulnerability in @eslint/plugin-kit versions before 0.2.3. Attackers can send special...

Nov 19, 2024
CVE-2024-49761
7.5

CVE-2024-49761 is a Regular Expression Denial of Service (ReDoS) vulnerability in REXML, Ruby's XML toolkit. It allows attackers to cause denial of se...

Oct 28, 2024
CVE-2020-26308
7.5

CVE-2020-26308 is a Regular Expression Denial of Service (ReDoS) vulnerability in validate.js library versions 0.13.1 and earlier. Attackers can craft...

Oct 26, 2024
CVE-2020-26311
7.5

CVE-2020-26311 is a Regular Expression Denial of Service (ReDoS) vulnerability in the useragent Node.js package. Attackers can cause denial of service...

Oct 26, 2024
CVE-2020-26304
7.5

Foundation front-end framework versions 6.3.3 and earlier contain vulnerable regular expressions that can be exploited for Regular Expression Denial o...

Oct 26, 2024
CVE-2024-48938
7.5

This vulnerability allows denial-of-service attacks against Znuny systems through specially crafted emails. Attackers can send emails containing HTML ...

Oct 11, 2024
CVE-2024-8124
7.5

This vulnerability in GitLab allows attackers to cause Denial of Service by sending a specific POST request to affected instances. All GitLab Communit...

Sep 12, 2024
CVE-2024-45296
7.5

CVE-2024-45296 is a denial-of-service vulnerability in the path-to-regexp library where certain path patterns generate inefficient regular expressions...

Sep 9, 2024
CVE-2024-3651
7.5

A denial-of-service vulnerability exists in the kjd/idna library's idna.encode() function where specially crafted input strings trigger quadratic comp...

Jul 7, 2024
CVE-2024-5552
7.5

This CVE describes a Regular Expression Denial of Service (ReDoS) vulnerability in kubeflow/kubeflow's email validation mechanism. Attackers can remot...

Jun 6, 2024
CVE-2024-4148
7.5

A Regular Expression Denial of Service (ReDoS) vulnerability in lunary-ai/lunary version 1.2.10 allows attackers to send specially crafted requests th...

Jun 1, 2024
CVE-2024-28716
7.5

CVE-2024-28716 is a remote code execution vulnerability in OpenStack Storlets yoga-eom's gateway.py component. It allows attackers to execute arbitrar...

Apr 30, 2024
CVE-2024-4056
7.5

CVE-2024-4056 is a denial-of-service vulnerability in M-Files Server that allows unauthenticated attackers to consume computing resources, potentially...

Apr 26, 2024
CVE-2024-22640
7.5

TCPDF versions up to 6.6.5 contain a ReDoS vulnerability in color parsing that allows attackers to cause denial of service by providing specially craf...

Apr 19, 2024
CVE-2024-28865
7.5

CVE-2024-28865 is a denial-of-service vulnerability in django-wiki where malicious article content can trigger a regular expression loop causing exces...

Mar 18, 2024
CVE-2023-51931
7.5

This vulnerability in URLite v3.1.0 allows attackers to cause denial of service (DoS) by sending specially crafted payloads to the URL parsing functio...

Feb 16, 2024
CVE-2024-21490
7.5

This CVE describes a regular expression denial of service (ReDoS) vulnerability in AngularJS versions 1.3.0 and above. Attackers can cause denial of s...

Feb 10, 2024
CVE-2024-23732
7.5

This vulnerability allows attackers to cause a denial of service (DoS) in Embedchain by sending specially crafted JSON data with long strings that tri...

Jan 21, 2024
CVE-2023-4316
7.5

Zod versions 3.21.0 through 3.22.3 contain a vulnerability where attackers can cause denial of service by sending specially crafted email addresses du...

Sep 28, 2023
CVE-2023-39663
7.5

MathJax versions up to 2.7.9 contain two regular expression denial-of-service (ReDoS) vulnerabilities in MathJax.js via the components pattern and mar...

Aug 29, 2023
CVE-2023-3994
7.5

This vulnerability allows attackers to cause a Denial of Service (DoS) in GitLab by sending specially crafted payloads to the preview_markdown endpoin...

Aug 2, 2023
CVE-2023-3364
7.5

This vulnerability allows attackers to cause denial of service (DoS) in GitLab by sending specially crafted payloads to the preview_markdown endpoint....

Aug 2, 2023
CVE-2023-3424
7.5

This vulnerability allows attackers to cause a Denial of Service (DoS) in GitLab by sending specially crafted payloads to the preview_markdown endpoin...

Jul 13, 2023
CVE-2023-32610
7.5

CVE-2023-32610 is a denial-of-service vulnerability in Mailform Pro CGI versions 4.3.1.2 and earlier that allows remote unauthenticated attackers to c...

Jun 29, 2023
CVE-2023-33289
7.5

The urlnorm crate through version 0.1.4 for Rust is vulnerable to Regular Expression Denial of Service (ReDos) via specially crafted URLs. This allows...

Jun 21, 2023
CVE-2023-2198
7.5

This vulnerability allows attackers to cause denial of service (DoS) in GitLab instances by sending specially crafted payloads to the preview_markdown...

Jun 7, 2023
CVE-2023-31606
7.5

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the sanitize_html function of the redcloth gem v4.0.0. Attackers can cause deni...

Jun 6, 2023
CVE-2023-32758
7.5

CVE-2023-32758 is a Regular Expression Denial of Service (ReDoS) vulnerability in giturlparse library versions through 1.2.2. When parsing maliciously...

May 15, 2023
CVE-2020-6817
7.5

This CVE describes a regular expression denial of service (ReDoS) vulnerability in Mozilla's bleach library when parsing style attributes. Attackers c...

Feb 16, 2023
CVE-2022-31147
7.5

The jQuery Validation Plugin versions before 1.19.5 contain a regular expression denial of service (ReDoS) vulnerability in the url2 method. Attackers...

Jul 14, 2022
CVE-2022-31781
7.5

Apache Tapestry versions up to 5.8.1 contain a Regular Expression Denial of Service (ReDoS) vulnerability in the ContentType class. Attackers could ca...

Jul 13, 2022

About CWE-1333 (CWE-1333)

Our database tracks 98 CVEs classified as CWE-1333, with 1 rated critical and 66 rated high severity. The average CVSS score for CWE-1333 vulnerabilities is 6.9.

External reference: View CWE-1333 on MITRE CWE →

Monitor CWE-1333 Vulnerabilities

Get alerted when new CWE-1333 CVEs affect your infrastructure.

Start Monitoring Free