CWE-407 · 164 kayıt
Inefficient Algorithmic Complexity
Bu sınıftaki CVE’ler
165 kayıt
| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
44Planlayın | CVE-2020-27223Kavram kanıtı | In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accepteclipse · jetty · CWE-407 | Orta5,3 | — | %78,0 | 26 Şub 2021 |
40Planlayın | CVE-2022-36021İstismar yok | Redis string pattern matching can be abused to achieve Denial of Serviceredis · redis · CWE-407 | Orta5,5 | — | %59,8 | 1 Mar 2023 |
34İzleyin | CVE-2026-55968İstismar yok | Apache Thrift: Node.js quadratic-time DoS in server receive transportsapache · thrift · CWE-407 | Yüksek8,7 | — | %1,0 | 27 Tem 2026 |
34İzleyin | CVE-2026-54892İstismar yok | Plug: quadratic-time decoding of nested query/body parameters enables denial of serviceelixir-plug · plug · CWE-407 | Yüksek8,7 | — | %0,9 | 23 Haz 2026 |
34İzleyin | CVE-2026-43967İstismar yok | Quadratic fragment-name uniqueness check causes denial of service in absintheabsinthe-graphql · absinthe · CWE-407 | Yüksek8,7 | — | %0,8 | 8 May 2026 |
34İzleyin | CVE-2026-59094İstismar yok | Pathway - Unauthenticated Denial of Service via Exponential Glob Pattern Matching in Document Storepathwaycom · pathway · CWE-407 | Yüksek8,7 | — | %0,8 | 2 Tem 2026 |
34İzleyin | CVE-2026-70453İstismar yok | rsync < 3.5.0 Algorithmic Complexity DoS via hash_search()rsyncproject · rsync · CWE-407 | Yüksek8,7 | — | %0,8 | 13 Ağu 2026 |
34İzleyin | CVE-2026-66046İstismar yok | Expat Denial of Service via storeAtts() Quadratic Complexitylibexpat project · libexpat · CWE-407 | Yüksek8,7 | — | %0,7 | 18 Ağu 2026 |
34İzleyin | CVE-2026-75005İstismar yok | Apache APISIX: Unauthenticated CPU-exhaustion DoSapache · apisix · CWE-407 | Yüksek8,7 | — | %0,7 | 27 Ağu 2026 |
34İzleyin | CVE-2026-75596İstismar yok | Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsingnetty · netty · CWE-407 | Yüksek8,7 | — | %0,7 | 19 Ağu 2026 |
34İzleyin | CVE-2026-90776İstismar yok | Nodemailer 9.1.0 through 10.0.4 Denial of Service via Quadratic Address Parsingnodemailer · nodemailer · CWE-407 | Yüksek8,7 | — | %0,7 | 13 Eyl 2026 |
34İzleyin | CVE-2026-87822İstismar yok | t-digest 3.1 through 3.3 Denial of Service via NaN Centroid Means in MergingDigest.fromBytestdunning · t-digest · CWE-407 | Yüksek8,7 | — | %0,7 | 9 Eyl 2026 |
34İzleyin | CVE-2026-59880İstismar yok | Immutable.js: Hash-collision algorithmic complexity denial of service in Immutable.Map/Setimmutable-js · immutable · CWE-407 | Yüksek8,7 | — | %0,7 | 8 Tem 2026 |
34İzleyin | CVE-2026-65623İstismar yok | Quadratic CPU blow-up reassembling fragmented WebSocket messages in Banditmtrudel · bandit · CWE-407 | Yüksek8,7 | — | %0,6 | 24 Tem 2026 |
34İzleyin | CVE-2026-85446İstismar yok | MOOS-IvP through 24.8.1 uFldNodeComms Quadratic Processing Denial of Servicemoos-ivp · moos-ivp · CWE-407 | Yüksek8,7 | — | %0,6 | 3 Eyl 2026 |
34İzleyin | CVE-2026-92987İstismar yok | roxmltree through 0.21.1 Denial of Service via Quadratic Parsingrazrfalcon · roxmltree · CWE-407 | Yüksek8,7 | — | %0,6 | 17 Eyl 2026 |
34İzleyin | CVE-2026-83613İstismar yok | xmldom: Quadratic-time attribute deduplicationxmldom · xmldom · CWE-407 | Yüksek8,7 | — | %0,6 | 1 Eyl 2026 |
34İzleyin | CVE-2026-13311İstismar yok | shell-quote parse() is quadratic in token count, enabling denial of serviceshell-quote project · shell-quote · CWE-407 | Yüksek8,7 | — | %0,6 | 25 Haz 2026 |
34İzleyin | CVE-2026-57480İstismar yok | Parse Server: Denial of service via exponential-time processing of deeply nested query operatorsparse-community · parse-server · CWE-407 | Yüksek8,7 | — | %0,6 | 8 Tem 2026 |
34İzleyin | CVE-2026-58226İstismar yok | Unauthenticated denial-of-service via unbounded HPACK integer decoding in hpaxelixir-mint · hpax · CWE-407 | Yüksek8,7 | — | %0,5 | 6 Tem 2026 |
34İzleyin | CVE-2026-81722İstismar yok | nltk PorterStemmer before 3.10.3 Quadratic-time DoSnltk · nltk · CWE-407 | Yüksek8,7 | — | %0,5 | 27 Ağu 2026 |
34İzleyin | CVE-2026-86429İstismar yok | commonmark before 2.9.1 Denial of Service via SmartPunct and Attributesthephpleague · commonmark · CWE-407 | Yüksek8,7 | — | %0,5 | 7 Eyl 2026 |
34İzleyin | CVE-2026-49250İstismar yok | Conform: parseSubmission vulnerable to CPU exhaustion when parsing many unique form fieldsedmundhung · conform · CWE-407 | Yüksek8,7 | — | %0,5 | 14 Eyl 2026 |
34İzleyin | CVE-2026-86433İstismar yok | commonmark 1.5.0 before 2.8.4 Denial of Service via Attributesthephpleague · commonmark · CWE-407 | Yüksek8,7 | — | %0,5 | 7 Eyl 2026 |
34İzleyin | CVE-2026-86434İstismar yok | commonmark 2.0.0 through 2.8.3 Denial of Service via Slug Collisionthephpleague · commonmark · CWE-407 | Yüksek8,7 | — | %0,5 | 7 Eyl 2026 |
- CVE-2020-2722344Planlayın
In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept
OrtaCVSS 5,3Kavram kanıtıEPSS %78eclipse · jetty26 Şub 2021
- CVE-2022-3602140Planlayın
Redis string pattern matching can be abused to achieve Denial of Service
OrtaCVSS 5,5İstismar yokEPSS %60redis · redis1 Mar 2023
- CVE-2026-5596834İzleyin
Apache Thrift: Node.js quadratic-time DoS in server receive transports
YüksekCVSS 8,7İstismar yokEPSS %1apache · thrift27 Tem 2026
- CVE-2026-5489234İzleyin
Plug: quadratic-time decoding of nested query/body parameters enables denial of service
YüksekCVSS 8,7İstismar yokEPSS %1elixir-plug · plug23 Haz 2026
- CVE-2026-4396734İzleyin
Quadratic fragment-name uniqueness check causes denial of service in absinthe
YüksekCVSS 8,7İstismar yokEPSS %1absinthe-graphql · absinthe8 May 2026
- CVE-2026-5909434İzleyin
Pathway - Unauthenticated Denial of Service via Exponential Glob Pattern Matching in Document Store
YüksekCVSS 8,7İstismar yokEPSS %1pathwaycom · pathway2 Tem 2026
- CVE-2026-7045334İzleyin
rsync < 3.5.0 Algorithmic Complexity DoS via hash_search()
YüksekCVSS 8,7İstismar yokEPSS %1rsyncproject · rsync13 Ağu 2026
- CVE-2026-6604634İzleyin
Expat Denial of Service via storeAtts() Quadratic Complexity
YüksekCVSS 8,7İstismar yokEPSS %1libexpat project · libexpat18 Ağu 2026
- CVE-2026-7500534İzleyin
Apache APISIX: Unauthenticated CPU-exhaustion DoS
YüksekCVSS 8,7İstismar yokEPSS %1apache · apisix27 Ağu 2026
- CVE-2026-7559634İzleyin
Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing
YüksekCVSS 8,7İstismar yokEPSS %1netty · netty19 Ağu 2026
- CVE-2026-9077634İzleyin
Nodemailer 9.1.0 through 10.0.4 Denial of Service via Quadratic Address Parsing
YüksekCVSS 8,7İstismar yokEPSS %1nodemailer · nodemailer13 Eyl 2026
- CVE-2026-8782234İzleyin
t-digest 3.1 through 3.3 Denial of Service via NaN Centroid Means in MergingDigest.fromBytes
YüksekCVSS 8,7İstismar yokEPSS %1tdunning · t-digest9 Eyl 2026
- CVE-2026-5988034İzleyin
Immutable.js: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set
YüksekCVSS 8,7İstismar yokEPSS %1immutable-js · immutable8 Tem 2026
- CVE-2026-6562334İzleyin
Quadratic CPU blow-up reassembling fragmented WebSocket messages in Bandit
YüksekCVSS 8,7İstismar yokEPSS %1mtrudel · bandit24 Tem 2026
- CVE-2026-8544634İzleyin
MOOS-IvP through 24.8.1 uFldNodeComms Quadratic Processing Denial of Service
YüksekCVSS 8,7İstismar yokEPSS %1moos-ivp · moos-ivp3 Eyl 2026
- CVE-2026-9298734İzleyin
roxmltree through 0.21.1 Denial of Service via Quadratic Parsing
YüksekCVSS 8,7İstismar yokEPSS %1razrfalcon · roxmltree17 Eyl 2026
- CVE-2026-8361334İzleyin
xmldom: Quadratic-time attribute deduplication
YüksekCVSS 8,7İstismar yokEPSS %1xmldom · xmldom1 Eyl 2026
- CVE-2026-1331134İzleyin
shell-quote parse() is quadratic in token count, enabling denial of service
YüksekCVSS 8,7İstismar yokEPSS %1shell-quote project · shell-quote25 Haz 2026
- CVE-2026-5748034İzleyin
Parse Server: Denial of service via exponential-time processing of deeply nested query operators
YüksekCVSS 8,7İstismar yokEPSS %1parse-community · parse-server8 Tem 2026
- CVE-2026-5822634İzleyin
Unauthenticated denial-of-service via unbounded HPACK integer decoding in hpax
YüksekCVSS 8,7İstismar yokEPSS %1elixir-mint · hpax6 Tem 2026
- CVE-2026-8172234İzleyin
nltk PorterStemmer before 3.10.3 Quadratic-time DoS
YüksekCVSS 8,7İstismar yokEPSS %1nltk · nltk27 Ağu 2026
- CVE-2026-8642934İzleyin
commonmark before 2.9.1 Denial of Service via SmartPunct and Attributes
YüksekCVSS 8,7İstismar yokEPSS %1thephpleague · commonmark7 Eyl 2026
- CVE-2026-4925034İzleyin
Conform: parseSubmission vulnerable to CPU exhaustion when parsing many unique form fields
YüksekCVSS 8,7İstismar yokEPSS %1edmundhung · conform14 Eyl 2026
- CVE-2026-8643334İzleyin
commonmark 1.5.0 before 2.8.4 Denial of Service via Attributes
YüksekCVSS 8,7İstismar yokEPSS %1thephpleague · commonmark7 Eyl 2026
- CVE-2026-8643434İzleyin
commonmark 2.0.0 through 2.8.3 Denial of Service via Slug Collision
YüksekCVSS 8,7İstismar yokEPSS %1thephpleague · commonmark7 Eyl 2026