Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 298 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.61% | — | Perl TIE Hash RegexAI | 22/8/2026 | 27/8/2026 | Tie::Hash::Regex versions before 2.0.0 for Perl will throw an exception on unparseable lookup keys. The FETCH, EXISTS and DELETE methods throw an exception when on malformed regular expressions. Each method falls back to a regex match when the key is not already stored in the hash, compiling the caller's key with a… | |
| Aplazada | Baja (1.9) | 0.11% | — | Kokke Tiny-regex-cAI | 8/6/2026 | 23/7/2026 | A flaw has been found in kokke tiny-regex-c up to f2632c6d9ed25272987471cdb8b70395c2460bdb. This vulnerability affects the function matchstar of the file re.c of the component Pattern Handler. This manipulation causes inefficient regular expression complexity. The attack is restricted to local execution. The exploit… | |
| Aplazada | Alta (7.5) | 0.28% | — | Youtube-regexAI | 7/5/2026 | 17/6/2026 | Regex Denial of Service in youtube-regex npm package through version 1.0.5. | |
| Modificada | Alta (7.5) | 0.89% | — | Pillarjs Path-to-regexp | 26/3/2026 | 9/9/2026 | Impact: A bad regular expression is generated any time you have multiple sequential optional groups (curly brace syntax), such as `{a}{b}{c}:z`. The generated regex grows exponentially with the number of groups, causing denial of service. Patches: Fixed in version 8.4.0. Workarounds: Limit the number of sequential… | |
| Analizada | Media (5.9) | 0.37% | — | Pillarjs Path-to-regexp | 26/3/2026 | 17/6/2026 | Impact: When using multiple wildcards, combined with at least one parameter, a regular expression can be generated that is vulnerable to ReDoS. This backtracking vulnerability requires the second wildcard to be somewhere other than the end of the path. Unsafe examples: /*foo-*bar-:baz /*a-:b-*c-:d /x/*a-:b/*c/y Safe… | |
| Analizada | Alta (7.5) | 0.62% | — | Pillarjs Path-to-regexp | 26/3/2026 | 17/6/2026 | Impact: A bad regular expression is generated any time you have three or more parameters within a single segment, separated by something that is not a period (.). For example, /:a-:b-:c or /:a-:b-:c-:d. The backtrack protection added in path-to-regexp@0.1.12 only prevents ambiguity for two parameters. With three or… | |
| Analizada | Media (5.6) | 0.28% | — | Malvineous Masseditregex | 3/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation Mediawiki - MassEditRegex Extension allows Stored XSS.This issue affects Mediawiki - MassEditRegex Extension: from 1.39.X before 1.39.12, from 1.42.X before 1.42.7, from 1.43.X before… | |
| Aplazada | Alta (7.7) | 0.79% | — | Pillarjs Path-to-regexpAI | 5/12/2024 | 17/6/2026 | path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. The regular expression that is vulnerable to backtracking can be generated in the 0.1.x release of path-to-regexp. Upgrade to 0.1.12. This… | |
| Analizada | Alta (8.7) | 0.48% | — | Talyssonoc Commonregexjs | 26/10/2024 | 17/6/2026 | CommonRegexJS is a CommonRegex port for JavaScript. All available versions contain one or more regular expressions that are vulnerable to Regular Expression Denial of Service (ReDoS). As of time of publication, no known patches are available. | |
| Aplazada | Alta (7.5) | 0.93% | — | Pillarjs Path-to-regexpAI | 9/9/2024 | 17/6/2026 | path-to-regexp turns path strings into a regular expressions. In certain cases, path-to-regexp will output a regular expression that can be exploited to cause poor performance. Because JavaScript is single threaded and regex matching runs on the main thread, poor performance will block the event loop and lead to a… | |
| Analizada | Media (5.3) | 0.80% | — | Nescalante Urlregex | 2/9/2024 | 17/6/2026 | A vulnerability was found in nescalante urlregex up to 0.5.0 and classified as problematic. This issue affects some unknown processing of the file index.js of the component Backtracking. The manipulation leads to inefficient regular expression complexity. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Alta (7.5) | 1.1% | — | Regexfn Project Regexfn | 27/6/2022 | 17/6/2026 | A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in regexfn v1.0.5 when validating crafted invalid emails. | |
| Modificada | Alta (7.5) | 1.1% | — | Todo-regex Project Todo-regex | 27/6/2022 | 17/6/2026 | A Regular Expression Denial of Service (ReDOS) vulnerability was discovered in todo-regex v0.1.1 when matching crafted invalid TODO statements. | |
| Modificada | Alta (7.5) | 1.5% | — | Semver-regex Project Semver-regex | 2/6/2022 | 17/6/2026 | An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the semver-regex npm package, when an attacker is able to supply arbitrary input to the test() method | |
| Modificada | Alta (7.5) | 1.3% | — | Url-regex Project Url-regex | 20/5/2022 | 17/6/2026 | All versions of package url-regex are vulnerable to Regular Expression Denial of Service (ReDoS) which can cause the CPU usage to crash. | |
| Modificada | Alta (7.5) | 14% | — | Rust-lang RegexFedoraproject FedoraDebian Linux | 8/3/2022 | 17/6/2026 | regex is an implementation of regular expressions for the Rust language. The regex crate features built-in mitigations to prevent denial of service attacks caused by untrusted regexes, or untrusted input matched by trusted regexes. Those (tunable) mitigations already provide sane defaults to prevent attacks. This… | |
| Modificada | Alta (7.5) | 3.6% | — | Ansi-regex Project Ansi-regexOracle Communications Cloud Native Core Policy | 17/9/2021 | 17/6/2026 | ansi-regex is vulnerable to Inefficient Regular Expression Complexity | |
| Modificada | Alta (7.5) | 1.5% | — | Semver-regex Project Semver-regex | 15/9/2021 | 17/6/2026 | semver-regex is vulnerable to Inefficient Regular Expression Complexity | |
| Modificada | Alta (7.5) | 2.7% | — | Url-regex Project Url-regex | 4/6/2020 | 17/6/2026 | all versions of url-regex are vulnerable to Regular Expression Denial of Service. An attacker providing a very long string in String.test can cause a Denial of Service. | |
| Modificada | Alta (7.5) | 2.4% | — | Irregex Project Irregex | 21/4/2017 | 17/6/2026 | The backtrack compilation code in the Irregex package (aka IrRegular Expressions) before 0.9.6 for Scheme allows remote attackers to cause a denial of service (memory consumption) via a crafted regular expression with a repeating pattern. | |
| Modificada | Media (5) | 2.7% | — | BoostBoost Regex Library | 17/1/2008 | 16/6/2026 | regex/v4/perl_matcher_non_recursive.hpp in the Boost regex library (aka Boost.Regex) in Boost 1.33 and 1.34 allows context-dependent attackers to cause a denial of service (failed assertion and crash) via an invalid regular expression. |