CWE-1333: CWE-1333

100
Total CVEs
1
Critical
68
High
6.9
Avg CVSS

Yearly Trend

2026
8
2025
30
2024
27
2023
14
2022
10

Top Affected Vendors

1 Gitlab 12
2 Fedoraproject 6
3 Lunary 4
4 Huggingface 4
5 Apache 4
6 Angularjs 3
7 Ruby Lang 3
8 Ibm 2
9 Debian 2
10 Opensuse 1

All CWE-1333 CVEs (100)

CVE-2021-40901
7.5

CVE-2021-40901 is a Regular Expression Denial of Service (ReDoS) vulnerability in scniro-validator v1.0.1 that allows attackers to cause excessive CPU...

Jun 27, 2022
CVE-2021-40899
7.5

CVE-2021-40899 is a Regular Expression Denial of Service (ReDoS) vulnerability in repo-git-downloader v0.1.1 that allows attackers to cause excessive ...

Jun 27, 2022
CVE-2021-40895
7.5

CVE-2021-40895 is a Regular Expression Denial of Service (ReDoS) vulnerability in todo-regex v0.1.1 that allows attackers to cause denial of service b...

Jun 27, 2022
CVE-2021-40897
7.5

CVE-2021-40897 is a Regular Expression Denial of Service (ReDoS) vulnerability in split-html-to-chars v1.0.5 that allows attackers to cause denial of ...

Jun 27, 2022
CVE-2021-40892
7.5

A Regular Expression Denial of Service (ReDoS) vulnerability exists in validate-color v2.1.0 where specially crafted invalid rgb(a) strings cause cata...

Jun 24, 2022
CVE-2022-26650
7.5

This vulnerability in Apache ShenYu allows attackers to cause resource exhaustion (denial of service) by injecting malicious regular expressions into ...

May 17, 2022
CVE-2022-25598
7.5

Apache DolphinScheduler's user registration feature contains a Regular Expression Denial of Service (ReDoS) vulnerability that allows attackers to cau...

Mar 30, 2022
CVE-2021-41817
7.5

CVE-2021-41817 is a regular expression denial of service (ReDoS) vulnerability in Ruby's date gem. Attackers can cause denial of service by sending sp...

Jan 1, 2022
CVE-2021-23490
7.5

This vulnerability in parse-link-header package allows attackers to cause Denial of Service (DoS) through specially crafted link headers that trigger ...

Dec 24, 2021
CVE-2021-45470
7.5

CVE-2021-45470 is a regular expression injection vulnerability in cve-search's DatabaseLayer.py that allows attackers to inject malicious regex patter...

Dec 23, 2021
CVE-2021-3765
7.5

CVE-2021-3765 is a regular expression denial of service (ReDoS) vulnerability in validator.js, a popular input validation library for Node.js. Attacke...

Nov 2, 2021
CVE-2021-23446
7.5

This vulnerability allows attackers to cause a Denial of Service (DoS) by exploiting a regular expression in the Handsontable JavaScript library. Appl...

Sep 29, 2021
CVE-2021-3822
7.5

CVE-2021-3822 is a regular expression denial of service (ReDoS) vulnerability in jsoneditor, a web-based JSON editor. Attackers can cause denial of se...

Sep 27, 2021
CVE-2021-3804
7.5

CVE-2021-3804 is a regular expression denial-of-service (ReDoS) vulnerability in Taro, a cross-platform development framework. Attackers can cause exc...

Sep 17, 2021
CVE-2021-3810
7.5

CVE-2021-3810 is a regular expression denial-of-service (ReDoS) vulnerability in code-server's URL path validation. Attackers can craft malicious URLs...

Sep 17, 2021
CVE-2021-3649
7.5

CVE-2021-3649 is a regular expression denial of service (ReDoS) vulnerability in Chatwoot's URL validation logic. Attackers can cause CPU exhaustion a...

Jul 16, 2021
CVE-2021-27291
7.5

CVE-2021-27291 is a Regular Expression Denial of Service (ReDoS) vulnerability in Pygments syntax highlighting library versions 1.1 through 2.7.3. Att...

Mar 17, 2021
CVE-2021-28092
7.5

The is-svg package for Node.js contains a vulnerable regular expression that allows attackers to cause Denial of Service (DoS) by providing specially ...

Mar 12, 2021
CVE-2021-26813
7.5

CVE-2021-26813 is a regular expression denial of service (ReDoS) vulnerability in markdown2, a Python Markdown processor. Attackers can cause extended...

Mar 3, 2021
CVE-2025-43764
6.5

This vulnerability allows authenticated users with Kaleo Workflow update permissions to submit malicious regular expressions in the Role Name search f...

Aug 23, 2025
CVE-2024-4025
6.5

A Denial of Service vulnerability in GitLab allows attackers to crash the application by uploading specially crafted markdown pages. This affects all ...

Jun 20, 2025
CVE-2024-12391
6.5

This vulnerability allows attackers to cause a denial of service by providing specially crafted regular expressions to the '解析项目源码(手�...

Mar 20, 2025
CVE-2024-10955
6.5

This CVE describes a Regular Expression Denial of Service (ReDoS) vulnerability in gaizhenbiao/chuanhuchatgpt where a regex pattern used to parse user...

Mar 20, 2025
CVE-2025-0367
6.5

A vulnerable regular expression pattern in Splunk's SA-ldapsearch add-on versions 3.1.0 and lower could allow attackers to cause denial of service thr...

Jan 30, 2025
CVE-2024-36751
6.5

This vulnerability in parse-uri v1.0.9 allows attackers to cause a Denial of Service (DoS) by sending specially crafted URLs that trigger inefficient ...

Jan 15, 2025
CVE-2024-39317
6.5

This CVE describes a denial-of-service vulnerability in Wagtail's parse_query_string function where specially crafted long strings without spaces caus...

Jul 11, 2024
CVE-2024-39316
6.5

This CVE describes a Regular Expression Denial of Service (ReDoS) vulnerability in Rack's HTTP Accept header parsing. Attackers can send specially cra...

Jul 2, 2024
CVE-2024-1493
6.5

This vulnerability allows attackers to perform a regular expression denial-of-service (ReDoS) attack against GitLab servers by exploiting inefficient ...

Jun 27, 2024
CVE-2024-1495
6.5

This CVE describes a denial-of-service vulnerability in GitLab CE/EE where an attacker can craft malicious files to trigger a ReDoS (Regular Expressio...

Jun 12, 2024
CVE-2024-1963
6.5

This CVE describes a regular expression denial of service (ReDoS) vulnerability in GitLab's Asana integration. An attacker can send specially crafted ...

Jun 12, 2024
CVE-2024-2651
6.5

This vulnerability allows attackers to cause denial of service (DoS) in GitLab instances by submitting maliciously crafted markdown content. All GitLa...

May 14, 2024
CVE-2023-6688
6.5

This vulnerability in GitLab's Google Chat Messages integration allows attackers to cause a denial-of-service (DoS) condition through a regular expres...

May 14, 2024
CVE-2025-26042
6.0

Uptime Kuma versions 1.23.0 and above contain a ReDoS vulnerability where an administrator creating a notification with a specially crafted string can...

Mar 17, 2025
CVE-2026-2327
5.3

This vulnerability allows attackers to cause a denial-of-service condition in markdown-it by exploiting a regular expression flaw. Attackers can send ...

Feb 12, 2026
CVE-2026-0668
5.3

This CVE describes an Inefficient Regular Expression Complexity vulnerability (Regular Expression Exponential Blowup) in the MediaWiki VisualData Exte...

Jan 7, 2026
CVE-2025-68142
5.3

PyMdown Extensions versions before 10.16.1 contain a ReDoS vulnerability in the figure caption extension that allows attackers to cause denial of serv...

Dec 16, 2025
CVE-2025-5197
5.3

A Regular Expression Denial of Service (ReDoS) vulnerability in Hugging Face Transformers allows attackers to cause excessive CPU consumption by provi...

Aug 6, 2025
CVE-2025-3264
5.3

A Regular Expression Denial of Service (ReDoS) vulnerability in Hugging Face Transformers library allows attackers to cause excessive CPU consumption ...

Jul 7, 2025
CVE-2025-25289
5.3

A Regular Expression Denial of Service (ReDoS) vulnerability exists in @octokit/request-error versions 1.0.0 through 6.1.6. Attackers can send special...

Feb 14, 2025
CVE-2025-25285
5.3

This vulnerability in @octokit/endpoint allows attackers to cause a regular expression denial-of-service (ReDoS) attack by crafting specific options p...

Feb 14, 2025
CVE-2024-4067
5.3

The NPM package micromatch prior to version 4.0.8 is vulnerable to Regular Expression Denial of Service (ReDoS) in the braces() function. Attackers ca...

May 14, 2024
CVE-2023-26116
5.3

This vulnerability in Angular's angular.copy() function allows attackers to cause Denial of Service (DoS) through Regular Expression Denial of Service...

Mar 30, 2023
CVE-2023-26118
5.3

This vulnerability allows attackers to cause Denial of Service (DoS) in Angular applications by submitting specially crafted URLs to input fields with...

Mar 30, 2023
CVE-2026-22809
4.4

A Regular Expression Denial of Service (ReDoS) vulnerability in tarteaucitron.js allows attackers to cause denial of service by sending specially craf...

Jan 13, 2026
CVE-2025-4690
4.3

This CVE describes a Regular Expression Denial of Service (ReDoS) vulnerability in AngularJS's linky filter. Attackers can craft malicious input that ...

Aug 19, 2025
CVE-2025-6069
4.3

This CVE describes a denial-of-service vulnerability in Python's html.parser.HTMLParser class where specially crafted malformed HTML inputs can trigge...

Jun 17, 2025
CVE-2023-6502
4.3

A denial-of-service vulnerability in GitLab allows attackers to crash the service by creating specially crafted wiki pages. This affects all GitLab Co...

May 23, 2024
CVE-2025-27220
4.0

A Regular Expression Denial of Service (ReDoS) vulnerability exists in the CGI gem for Ruby versions before 0.4.2. This vulnerability allows attackers...

Mar 4, 2025
CVE-2025-69873
2.9

CVE-2025-69873 is a Regular Expression Denial of Service (ReDoS) vulnerability in ajv (Another JSON Schema Validator) that allows attackers to cause C...

Feb 11, 2026
CVE-2026-25547
N/A

The @isaacs/brace-expansion library is vulnerable to denial of service (DoS) through unbounded brace range expansion. Attackers can crash Node.js proc...

Feb 4, 2026

About CWE-1333 (CWE-1333)

Our database tracks 100 CVEs classified as CWE-1333, with 1 rated critical and 68 rated high severity. The average CVSS score for CWE-1333 vulnerabilities is 6.9.

External reference: View CWE-1333 on MITRE CWE →

Monitor CWE-1333 Vulnerabilities

Get alerted when new CWE-1333 CVEs affect your infrastructure.

Start Monitoring Free