CWE-407 · 165 записей
Inefficient Algorithmic Complexity
CVE этого класса
165 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
44В плане | CVE-2020-27223Proof of concept | In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accepteclipse · jetty · CWE-407 | Средняя5,3 | — | 78,0 % | 26 февр. 2021 г. |
40В плане | CVE-2022-36021Эксплойта нет | Redis string pattern matching can be abused to achieve Denial of Serviceredis · redis · CWE-407 | Средняя5,5 | — | 59,8 % | 1 мар. 2023 г. |
34Наблюдать | CVE-2026-55968Эксплойта нет | Apache Thrift: Node.js quadratic-time DoS in server receive transportsapache · thrift · CWE-407 | Высокая8,7 | — | 1,0 % | 27 июл. 2026 г. |
34Наблюдать | CVE-2026-54892Эксплойта нет | Plug: quadratic-time decoding of nested query/body parameters enables denial of serviceelixir-plug · plug · CWE-407 | Высокая8,7 | — | 0,9 % | 23 июн. 2026 г. |
34Наблюдать | CVE-2026-43967Эксплойта нет | Quadratic fragment-name uniqueness check causes denial of service in absintheabsinthe-graphql · absinthe · CWE-407 | Высокая8,7 | — | 0,8 % | 8 мая 2026 г. |
34Наблюдать | CVE-2026-59094Эксплойта нет | Pathway - Unauthenticated Denial of Service via Exponential Glob Pattern Matching in Document Storepathwaycom · pathway · CWE-407 | Высокая8,7 | — | 0,8 % | 2 июл. 2026 г. |
34Наблюдать | CVE-2026-70453Эксплойта нет | rsync < 3.5.0 Algorithmic Complexity DoS via hash_search()rsyncproject · rsync · CWE-407 | Высокая8,7 | — | 0,8 % | 13 авг. 2026 г. |
34Наблюдать | CVE-2026-66046Эксплойта нет | Expat Denial of Service via storeAtts() Quadratic Complexitylibexpat project · libexpat · CWE-407 | Высокая8,7 | — | 0,7 % | 18 авг. 2026 г. |
34Наблюдать | CVE-2026-75005Эксплойта нет | Apache APISIX: Unauthenticated CPU-exhaustion DoSapache · apisix · CWE-407 | Высокая8,7 | — | 0,7 % | 27 авг. 2026 г. |
34Наблюдать | CVE-2026-75596Эксплойта нет | Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsingnetty · netty · CWE-407 | Высокая8,7 | — | 0,7 % | 19 авг. 2026 г. |
34Наблюдать | CVE-2026-90776Эксплойта нет | Nodemailer 9.1.0 through 10.0.4 Denial of Service via Quadratic Address Parsingnodemailer · nodemailer · CWE-407 | Высокая8,7 | — | 0,7 % | 13 сент. 2026 г. |
34Наблюдать | CVE-2026-87822Эксплойта нет | t-digest 3.1 through 3.3 Denial of Service via NaN Centroid Means in MergingDigest.fromBytestdunning · t-digest · CWE-407 | Высокая8,7 | — | 0,7 % | 9 сент. 2026 г. |
34Наблюдать | CVE-2026-59880Эксплойта нет | Immutable.js: Hash-collision algorithmic complexity denial of service in Immutable.Map/Setimmutable-js · immutable · CWE-407 | Высокая8,7 | — | 0,7 % | 8 июл. 2026 г. |
34Наблюдать | CVE-2026-65623Эксплойта нет | Quadratic CPU blow-up reassembling fragmented WebSocket messages in Banditmtrudel · bandit · CWE-407 | Высокая8,7 | — | 0,6 % | 24 июл. 2026 г. |
34Наблюдать | CVE-2026-92987Эксплойта нет | roxmltree through 0.21.1 Denial of Service via Quadratic Parsingrazrfalcon · roxmltree · CWE-407 | Высокая8,7 | — | 0,6 % | 17 сент. 2026 г. |
34Наблюдать | CVE-2026-85446Эксплойта нет | MOOS-IvP through 24.8.1 uFldNodeComms Quadratic Processing Denial of Servicemoos-ivp · moos-ivp · CWE-407 | Высокая8,7 | — | 0,6 % | 3 сент. 2026 г. |
34Наблюдать | CVE-2026-83613Эксплойта нет | xmldom: Quadratic-time attribute deduplicationxmldom · xmldom · CWE-407 | Высокая8,7 | — | 0,6 % | 1 сент. 2026 г. |
34Наблюдать | CVE-2026-13311Эксплойта нет | shell-quote parse() is quadratic in token count, enabling denial of serviceshell-quote project · shell-quote · CWE-407 | Высокая8,7 | — | 0,6 % | 25 июн. 2026 г. |
34Наблюдать | CVE-2026-57480Эксплойта нет | Parse Server: Denial of service via exponential-time processing of deeply nested query operatorsparse-community · parse-server · CWE-407 | Высокая8,7 | — | 0,6 % | 8 июл. 2026 г. |
34Наблюдать | CVE-2026-58226Эксплойта нет | Unauthenticated denial-of-service via unbounded HPACK integer decoding in hpaxelixir-mint · hpax · CWE-407 | Высокая8,7 | — | 0,5 % | 6 июл. 2026 г. |
34Наблюдать | CVE-2026-81722Эксплойта нет | nltk PorterStemmer before 3.10.3 Quadratic-time DoSnltk · nltk · CWE-407 | Высокая8,7 | — | 0,5 % | 27 авг. 2026 г. |
34Наблюдать | CVE-2026-86429Эксплойта нет | commonmark before 2.9.1 Denial of Service via SmartPunct and Attributesthephpleague · commonmark · CWE-407 | Высокая8,7 | — | 0,5 % | 7 сент. 2026 г. |
34Наблюдать | CVE-2026-49250Эксплойта нет | Conform: parseSubmission vulnerable to CPU exhaustion when parsing many unique form fieldsedmundhung · conform · CWE-407 | Высокая8,7 | — | 0,5 % | 14 сент. 2026 г. |
34Наблюдать | CVE-2026-86434Эксплойта нет | commonmark 2.0.0 through 2.8.3 Denial of Service via Slug Collisionthephpleague · commonmark · CWE-407 | Высокая8,7 | — | 0,5 % | 7 сент. 2026 г. |
34Наблюдать | CVE-2026-86433Эксплойта нет | commonmark 1.5.0 before 2.8.4 Denial of Service via Attributesthephpleague · commonmark · CWE-407 | Высокая8,7 | — | 0,5 % | 7 сент. 2026 г. |
- CVE-2020-2722344В плане
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept
СредняяCVSS 5,3Proof of conceptEPSS 78 %eclipse · jetty26 февр. 2021 г.
- CVE-2022-3602140В плане
Redis string pattern matching can be abused to achieve Denial of Service
СредняяCVSS 5,5Эксплойта нетEPSS 60 %redis · redis1 мар. 2023 г.
- CVE-2026-5596834Наблюдать
Apache Thrift: Node.js quadratic-time DoS in server receive transports
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %apache · thrift27 июл. 2026 г.
- CVE-2026-5489234Наблюдать
Plug: quadratic-time decoding of nested query/body parameters enables denial of service
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %elixir-plug · plug23 июн. 2026 г.
- CVE-2026-4396734Наблюдать
Quadratic fragment-name uniqueness check causes denial of service in absinthe
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %absinthe-graphql · absinthe8 мая 2026 г.
- CVE-2026-5909434Наблюдать
Pathway - Unauthenticated Denial of Service via Exponential Glob Pattern Matching in Document Store
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %pathwaycom · pathway2 июл. 2026 г.
- CVE-2026-7045334Наблюдать
rsync < 3.5.0 Algorithmic Complexity DoS via hash_search()
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %rsyncproject · rsync13 авг. 2026 г.
- CVE-2026-6604634Наблюдать
Expat Denial of Service via storeAtts() Quadratic Complexity
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %libexpat project · libexpat18 авг. 2026 г.
- CVE-2026-7500534Наблюдать
Apache APISIX: Unauthenticated CPU-exhaustion DoS
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %apache · apisix27 авг. 2026 г.
- CVE-2026-7559634Наблюдать
Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %netty · netty19 авг. 2026 г.
- CVE-2026-9077634Наблюдать
Nodemailer 9.1.0 through 10.0.4 Denial of Service via Quadratic Address Parsing
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %nodemailer · nodemailer13 сент. 2026 г.
- CVE-2026-8782234Наблюдать
t-digest 3.1 through 3.3 Denial of Service via NaN Centroid Means in MergingDigest.fromBytes
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %tdunning · t-digest9 сент. 2026 г.
- CVE-2026-5988034Наблюдать
Immutable.js: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %immutable-js · immutable8 июл. 2026 г.
- CVE-2026-6562334Наблюдать
Quadratic CPU blow-up reassembling fragmented WebSocket messages in Bandit
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %mtrudel · bandit24 июл. 2026 г.
- CVE-2026-9298734Наблюдать
roxmltree through 0.21.1 Denial of Service via Quadratic Parsing
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %razrfalcon · roxmltree17 сент. 2026 г.
- CVE-2026-8544634Наблюдать
MOOS-IvP through 24.8.1 uFldNodeComms Quadratic Processing Denial of Service
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %moos-ivp · moos-ivp3 сент. 2026 г.
- CVE-2026-8361334Наблюдать
xmldom: Quadratic-time attribute deduplication
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %xmldom · xmldom1 сент. 2026 г.
- CVE-2026-1331134Наблюдать
shell-quote parse() is quadratic in token count, enabling denial of service
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %shell-quote project · shell-quote25 июн. 2026 г.
- CVE-2026-5748034Наблюдать
Parse Server: Denial of service via exponential-time processing of deeply nested query operators
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %parse-community · parse-server8 июл. 2026 г.
- CVE-2026-5822634Наблюдать
Unauthenticated denial-of-service via unbounded HPACK integer decoding in hpax
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %elixir-mint · hpax6 июл. 2026 г.
- CVE-2026-8172234Наблюдать
nltk PorterStemmer before 3.10.3 Quadratic-time DoS
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %nltk · nltk27 авг. 2026 г.
- CVE-2026-8642934Наблюдать
commonmark before 2.9.1 Denial of Service via SmartPunct and Attributes
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %thephpleague · commonmark7 сент. 2026 г.
- CVE-2026-4925034Наблюдать
Conform: parseSubmission vulnerable to CPU exhaustion when parsing many unique form fields
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %edmundhung · conform14 сент. 2026 г.
- CVE-2026-8643434Наблюдать
commonmark 2.0.0 through 2.8.3 Denial of Service via Slug Collision
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %thephpleague · commonmark7 сент. 2026 г.
- CVE-2026-8643334Наблюдать
commonmark 1.5.0 before 2.8.4 Denial of Service via Attributes
ВысокаяCVSS 8,7Эксплойта нетEPSS 1 %thephpleague · commonmark7 сент. 2026 г.