Date::Manip versions through 6.99 for Perl allow CPU exhaustion via quadratic backtracking in the unanchored time substi
Inefficient Regular Expression Complexity vulnerability in the CSS scrubber in rrrene html_sanitize_ex allows an unauthe
pymdown-extensions is a collection of extensions for the Python Markdown library. In versions up to and including 11.0,
crmne/ruby_llm at commit fa6f279847d6d7027814539d9c0dfc3bbdfd2a83 contains a polynomial-time regular expression denial-o
ParseAcceptLanguage quadratic-time DoS via Locale middleware on unauthenticated requests
sqlparse is a non-validating SQL parser module for Python. Prior to 0.6.0, SQL_REGEX in sqlparse/keywords.py and the per
Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's email subaddressing
The URLS regular expression in nltk/tokenize/casual.py, compiled into TweetTokenizer.WORD_RE and applied by TweetTokeniz
SAP S/4HANA (Private Cloud) uses a third-party component that contains a Regular Expression Denial of Service (ReDoS) vu
Nokogiri versions before 1.19.3 contain regular expression denial of service vulnerabilities in the CSS selector tokeniz
NLTK versions before 3.10.0 contain a regular expression denial of service vulnerability in Text.findall() and TokenSear
AutoGPT is a platform that allows users to create, deploy, and manage continuous artificial intelligence agents that aut
OpenClaw versions prior to 2026.2.19 construct RegExp objects directly from unescaped Feishu mention metadata in the str
PraisonAI is a multi-agent teams system. Prior to version 4.5.90, MCPToolIndex.search_tools() compiles a caller-supplied
Nautobot is a Network Source of Truth and Network Automation Platform. Prior to 2.4.33 and 3.1.2, Nautobot UI object-bul
LobeChat before version 2.2.10-canary.15 contains a regular expression denial of service (ReDoS) vulnerability that allo
A flaw was found in `guardrails-detectors`, a component of Red Hat OpenShift AI. This vulnerability, known as Regular Ex
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.2 before 0.10.0, the SKIL
Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10.11.19 fail to validate the length and content of m
Grav before 2.0.4 contains a regular expression denial of service (ReDoS) vulnerability in the regex_replace filter and
A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through 5.0.0. The
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automatio
Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built
Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to version 0.37.0, cpp-httplib u
Impact: When using multiple wildcards, combined with at least one parameter, a regular expression can be generated that
NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgrep module. The _tgrep
A flaw was found in libssh. A remote attacker, by controlling client configuration files or known_hosts files, could cra
Giskard is an open-source testing framework for AI models. In versions prior to 1.0.2b1, the RegexMatching check passes
ShellHub is a centralized SSH gateway. Prior to 0.24.2, the device list endpoint accepts user-controlled identifiers in
Inefficient Regular Expression Complexity vulnerability in Wikimedia Foundation MediaWiki - VisualData Extension allows
pypdf is a free and open-source pure-python PDF library. Prior to version 6.6.0, pypdf has possible long runtimes for ma
Versions of the package markdown-it from 13.0.0 and before 14.1.1 are vulnerable to Regular Expression Denial of Service
Active Support is a toolkit of support libraries and Ruby core extensions extracted from the Rails framework. `NumberToD
A weakness has been identified in Zod jsVideoUrlParser up to 0.5.1. The impacted element is the function getTime in the
Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in
UAParser.js is a JavaScript library to detect browsers, operating systems, CPUs, and devices from user-agent data. From
SvelteKit is a framework for rapidly developing robust, performant web applications using Svelte. Prior to 2.70.2, the c
Hono is a Web application framework that provides support for any JavaScript runtime. Prior to 4.12.34, the built-in COR
vLLM is an inference and serving engine for large language models. Prior to 0.26.0, the structured_outputs.regex paramet
Inefficient Regular Expression Complexity (CWE-1333) in the AI Inference Anonymization Engine in Kibana can lead Denial
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and
tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.29.0, a Regular Expression Denial of Service (R
A security vulnerability has been detected in Enderfga claw-orchestrator up to 3.7.0. The impacted element is the functi
A security flaw has been discovered in wonderwhy-er DesktopCommanderMCP up to 0.2.38. This impacts an unknown function o
A weakness has been identified in johnhuang316 code-index-mcp up to 2.14.0. Affected is the function is_safe_regex_patte
vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Severa
CyberChef is a web app for encryption, encoding, compression, and data analysis. Prior to 11.3.0, CyberChef's pretty-rec
fast-jwt provides fast JSON Web Token (JWT) implementation. From 5.0.0 to 6.2.0, a denial-of-service condition exists in
Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provid
Frequently Asked Questions
What is CWE-1333?
CWE-1333 (CWE-1333) is a weakness category in the Common Weakness Enumeration (CWE) system maintained by MITRE. It describes a class of software or hardware vulnerability that can lead to security issues.
How many CVEs are classified as CWE-1333?
There are 119 CVE records associated with CWE-1333 in our database. Of these, 2 are critical severity, 59 are high severity, and 38 are medium severity.
How can I protect against CWE-1333 vulnerabilities?
Protection strategies depend on the specific weakness type. General measures include input validation, secure coding practices, regular security testing, and keeping software up to date. CyberStrike can help by automatically scanning your infrastructure for vulnerabilities related to CWE-1333 using AI-powered security agents.
Detect CWE-1333 Vulnerabilities
CyberStrike's AI agents automatically detect cwe-1333 vulnerabilities across your infrastructure.
Get Started