İçeriğe atla
Noroxi

CWE-407 · 164 kayıt

Inefficient Algorithmic Complexity

Bu sınıftaki CVE’ler

165 kayıt

  • CVE-2020-27223
    44Planlayın

    In Eclipse Jetty 9.4.6.v20170531 to 9.4.36.v20210114 (inclusive), 10.0.0, and 11.0.0 when Jetty handles a request containing multiple Accept

    OrtaCVSS 5,3Kavram kanıtıEPSS %78

    eclipse · jetty26 Şub 2021

  • CVE-2022-36021
    40Planlayın

    Redis string pattern matching can be abused to achieve Denial of Service

    OrtaCVSS 5,5İstismar yokEPSS %60

    redis · redis1 Mar 2023

  • CVE-2026-55968
    34İzleyin

    Apache Thrift: Node.js quadratic-time DoS in server receive transports

    YüksekCVSS 8,7İstismar yokEPSS %1

    apache · thrift27 Tem 2026

  • CVE-2026-54892
    34İzleyin

    Plug: quadratic-time decoding of nested query/body parameters enables denial of service

    YüksekCVSS 8,7İstismar yokEPSS %1

    elixir-plug · plug23 Haz 2026

  • CVE-2026-43967
    34İzleyin

    Quadratic fragment-name uniqueness check causes denial of service in absinthe

    YüksekCVSS 8,7İstismar yokEPSS %1

    absinthe-graphql · absinthe8 May 2026

  • CVE-2026-59094
    34İzleyin

    Pathway - Unauthenticated Denial of Service via Exponential Glob Pattern Matching in Document Store

    YüksekCVSS 8,7İstismar yokEPSS %1

    pathwaycom · pathway2 Tem 2026

  • CVE-2026-70453
    34İzleyin

    rsync < 3.5.0 Algorithmic Complexity DoS via hash_search()

    YüksekCVSS 8,7İstismar yokEPSS %1

    rsyncproject · rsync13 Ağu 2026

  • CVE-2026-66046
    34İzleyin

    Expat Denial of Service via storeAtts() Quadratic Complexity

    YüksekCVSS 8,7İstismar yokEPSS %1

    libexpat project · libexpat18 Ağu 2026

  • CVE-2026-75005
    34İzleyin

    Apache APISIX: Unauthenticated CPU-exhaustion DoS

    YüksekCVSS 8,7İstismar yokEPSS %1

    apache · apisix27 Ağu 2026

  • CVE-2026-75596
    34İzleyin

    Netty: Fragmented ClientHello records trigger quadratic pre-handshake reassembly in default SNI parsing

    YüksekCVSS 8,7İstismar yokEPSS %1

    netty · netty19 Ağu 2026

  • CVE-2026-90776
    34İzleyin

    Nodemailer 9.1.0 through 10.0.4 Denial of Service via Quadratic Address Parsing

    YüksekCVSS 8,7İstismar yokEPSS %1

    nodemailer · nodemailer13 Eyl 2026

  • CVE-2026-87822
    34İzleyin

    t-digest 3.1 through 3.3 Denial of Service via NaN Centroid Means in MergingDigest.fromBytes

    YüksekCVSS 8,7İstismar yokEPSS %1

    tdunning · t-digest9 Eyl 2026

  • CVE-2026-59880
    34İzleyin

    Immutable.js: Hash-collision algorithmic complexity denial of service in Immutable.Map/Set

    YüksekCVSS 8,7İstismar yokEPSS %1

    immutable-js · immutable8 Tem 2026

  • CVE-2026-65623
    34İzleyin

    Quadratic CPU blow-up reassembling fragmented WebSocket messages in Bandit

    YüksekCVSS 8,7İstismar yokEPSS %1

    mtrudel · bandit24 Tem 2026

  • CVE-2026-85446
    34İzleyin

    MOOS-IvP through 24.8.1 uFldNodeComms Quadratic Processing Denial of Service

    YüksekCVSS 8,7İstismar yokEPSS %1

    moos-ivp · moos-ivp3 Eyl 2026

  • CVE-2026-92987
    34İzleyin

    roxmltree through 0.21.1 Denial of Service via Quadratic Parsing

    YüksekCVSS 8,7İstismar yokEPSS %1

    razrfalcon · roxmltree17 Eyl 2026

  • CVE-2026-83613
    34İzleyin

    xmldom: Quadratic-time attribute deduplication

    YüksekCVSS 8,7İstismar yokEPSS %1

    xmldom · xmldom1 Eyl 2026

  • CVE-2026-13311
    34İzleyin

    shell-quote parse() is quadratic in token count, enabling denial of service

    YüksekCVSS 8,7İstismar yokEPSS %1

    shell-quote project · shell-quote25 Haz 2026

  • CVE-2026-57480
    34İzleyin

    Parse Server: Denial of service via exponential-time processing of deeply nested query operators

    YüksekCVSS 8,7İstismar yokEPSS %1

    parse-community · parse-server8 Tem 2026

  • CVE-2026-58226
    34İzleyin

    Unauthenticated denial-of-service via unbounded HPACK integer decoding in hpax

    YüksekCVSS 8,7İstismar yokEPSS %1

    elixir-mint · hpax6 Tem 2026

  • CVE-2026-81722
    34İzleyin

    nltk PorterStemmer before 3.10.3 Quadratic-time DoS

    YüksekCVSS 8,7İstismar yokEPSS %1

    nltk · nltk27 Ağu 2026

  • CVE-2026-86429
    34İzleyin

    commonmark before 2.9.1 Denial of Service via SmartPunct and Attributes

    YüksekCVSS 8,7İstismar yokEPSS %1

    thephpleague · commonmark7 Eyl 2026

  • CVE-2026-49250
    34İzleyin

    Conform: parseSubmission vulnerable to CPU exhaustion when parsing many unique form fields

    YüksekCVSS 8,7İstismar yokEPSS %1

    edmundhung · conform14 Eyl 2026

  • CVE-2026-86433
    34İzleyin

    commonmark 1.5.0 before 2.8.4 Denial of Service via Attributes

    YüksekCVSS 8,7İstismar yokEPSS %1

    thephpleague · commonmark7 Eyl 2026

  • CVE-2026-86434
    34İzleyin

    commonmark 2.0.0 through 2.8.3 Denial of Service via Slug Collision

    YüksekCVSS 8,7İstismar yokEPSS %1

    thephpleague · commonmark7 Eyl 2026

Tüm zafiyet sınıfları