Browse and filter security vulnerabilities across ecosystems
Browse and filter security vulnerabilities across ecosystems
ReDoS in Open Mercato
HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
JSONata: Malicious inputs to "$toMillis" function can cause resource exhaustion
HTTP::Date versions before 6.08 for Perl allow CPU exhaustion via polynomial regex backtracking in parse_date
Grav < 2.0.4 ReDoS via regex_replace in Sandbox
HAPI FHIR: ReDoS via FHIRPath matches()/replaceMatches() in FHIR Validator HTTP Endpoint
UAParser.js: Unbounded `Sec-CH-UA-Model` parsing can trigger ReDoS in `withClientHints()`
Soup Sieve: Regular Expression Denial of Service (ReDoS) in soupsieve Selector Parser
linkify-it: Quadratic algorithmic complexity in LinkifyIt#match scan loop
Symfony: YAML Parser ReDoS via Catastrophic Backtracking in Parser::cleanup() Regex
Symfony: [Yaml] Harden the parser when handling untrusted input
Symfony: JsonPath Evaluates Attacker-Controlled Regular Expressions in match()/search() Without Limits — ReDoS
Crafted message attachment causes client-side denial of service via markdown parser regex backtracking in Mattermost
Phalcon: Catastrophic backtracking (ReDoS) in the default Phalcon Router route lead to remote unauthenticated DoS
Open WebUI: ReDoS in skill-mention regexes causes whole-instance DoS on default config
HAPI FHIR: DSTU2 FHIRPathEngine.matches() missing RegexTimeout protection allows ReDoS
Guardrails-detectors: guardrails-detectors: unauthenticated regular-expression denial of service (redos) via detector_params.regex
Mistune block_parser: quadratic-time parsing on long lists of repeated reference-link definitions
inline_parser: quadratic-time parsing on long runs of `**x**` and `***x***` emphasis pairs
Mistune plugins/formatting: quadratic-time parsing on long runs of `~~x~~`, `==x==`, and `^^x^^` markers (strikethrough / mark / insert)
Showing 1 - 20 of 1,000+ results