CWE-407— Inefficient Algorithmic Complexity
An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.— MITRE CWE catalog
217 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-407page 3 of 5
- CVE-2026-34230HIGHCVSS 7.5EG 7.52026-04-02
Rack is a modular Ruby web server interface. Prior to versions 2.2.23, 3.1.21, and 3.2.6, Rack::Utils.select_best_encoding processes Accept-Encoding values with quadratic time complexity when the header contains many wildcard (*) entries. …
- CVE-2026-31937HIGHCVSS 7.5EG 7.52026-04-02
Suricata is a network IDS, IPS and NSM engine. Prior to version 7.0.15, inefficiency in DCERPC buffering can lead to a performance degradation. This issue has been patched in version 7.0.15.
- CVE-2026-31934HIGHCVSS 7.5EG 7.52026-04-02
Suricata is a network IDS, IPS and NSM engine. From version 8.0.0 to before version 8.0.4, there is a quadratic complexity issue when searching for URLs in mime encoded messages over SMTP leading to a performance impact. This issue has bee…
- CVE-2026-31933HIGHCVSS 7.5EG 7.52026-04-02
Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, specially crafted traffic can cause Suricata to slow down, affecting performance in IDS mode. This issue has been patched in versions 7.0.15 and 8.0.4.
- CVE-2026-31932HIGHCVSS 7.5EG 7.52026-04-02
Suricata is a network IDS, IPS and NSM engine. Prior to versions 7.0.15 and 8.0.4, inefficiency in KRB5 buffering can lead to performance degradation. This issue has been patched in versions 7.0.15 and 8.0.4.
- CVE-2026-34573HIGHCVSS 7.5EG 7.52026-03-31
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to versions 8.6.68 and 9.7.0-alpha.12, the GraphQL query complexity validator can be exploited to cause a denial-of-service by se…
- CVE-2026-3988HIGHCVSS 7.5EG 7.52026-03-25
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.5 before 18.8.7, 18.9 before 18.9.3, and 18.10 before 18.10.1 that could have allowed an unauthenticated user to cause a denial of service by making the GitLab i…
- CVE-2026-27903HIGHCVSS 7.5EG 7.52026-02-26
minimatch is a minimal matching utility for converting glob expressions into JavaScript RegExp objects. Prior to version 10.2.3, 9.0.7, 8.0.6, 7.4.8, 6.2.2, 5.1.8, 4.2.5, and 3.1.3, `matchOne()` performs unbounded recursive backtracking wh…
- CVE-2026-1285HIGHCVSS 7.5EG 7.52026-02-03
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `django.utils.text.Truncator.chars()` and `Truncator.words()` methods (with `html=True`) and the `truncatechars_html` and `truncatewords_html` template …
- CVE-2025-14550HIGHCVSS 7.5EG 7.52026-02-03
An issue was discovered in 6.0 before 6.0.2, 5.2 before 5.2.11, and 4.2 before 4.2.28. `ASGIRequest` allows a remote attacker to cause a potential denial-of-service via a crafted request with multiple duplicate headers. Earlier, unsupporte…
- CVE-2025-64460HIGHCVSS 7.5EG 7.52025-12-02
An issue was discovered in 5.2 before 5.2.9, 5.1 before 5.1.15, and 4.2 before 4.2.27. Algorithmic complexity in `django.core.serializers.xml_serializer.getInnerText()` allows a remote attacker to cause a potential denial-of-service attack…
- CVE-2025-11230HIGHCVSS 7.5EG 7.52025-11-19
Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests.
- CVE-2025-64458HIGHCVSS 7.5EG 7.52025-11-05
An issue was discovered in 5.1 before 5.1.14, 4.2 before 4.2.26, and 5.2 before 5.2.8. NFKC normalization in Python is slow on Windows. As a consequence, `django.http.HttpResponseRedirect`, `django.http.HttpResponsePermanentRedirect`, and …
- CVE-2025-58187HIGHCVSS 7.5EG 7.52025-10-29
Due to the design of the name constraint checking algorithm, the processing time of some inputs scale non-linearly with respect to the size of the certificate. This affects programs which validate arbitrary certificate chains.
- CVE-2025-62727HIGHCVSS 7.5EG 7.52025-10-28
Starlette is a lightweight ASGI framework/toolkit. Starting in version 0.39.0 and prior to version 0.49.1 , an unauthenticated attacker can send a crafted HTTP Range header that triggers quadratic-time processing in Starlette's FileRespons…
- CVE-2025-27209HIGHCVSS 7.5EG 7.52025-07-18
The V8 release used in Node.js v24.0.0 has changed how string hashes are computed using rapidhash. This implementation re-introduces the HashDoS vulnerability as an attacker who can control the strings to be hashed can generate many hash c…
- CVE-2024-9631HIGHCVSS 7.5EG 7.52025-02-05
An issue was discovered in GitLab CE/EE affecting all versions starting from 13.6 prior to 17.2.9, starting from 17.3 prior to 17.3.5, and starting from 17.4 prior to 17.4.2, where viewing diffs of MR with conflicts can be slow.
- CVE-2024-8233HIGHCVSS 7.5EG 7.52024-12-12
An issue has been discovered in GitLab CE/EE affecting all versions from 9.4 before 17.4.6, 17.5 before 17.5.4, and 17.6 before 17.6.2. An attacker could cause a denial of service with requests for diff files on a commit or merge request.
- CVE-2024-43485HIGHCVSS 7.5EG 7.52024-10-08
.NET and Visual Studio Denial of Service Vulnerability
- CVE-2024-43484HIGHCVSS 7.5EG 7.52024-10-08
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
- CVE-2024-43483HIGHCVSS 7.5EG 7.52024-10-08
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
- CVE-2023-4408HIGHCVSS 7.5EG 7.52024-02-13
The DNS message parsing code in `named` includes a section whose computational complexity is overly high. It does not cause problems for typical DNS traffic, but crafted queries and responses may cause excessive CPU load on the affected `n…
- CVE-2024-23684HIGHCVSS 7.5EG 7.52024-01-19
Inefficient algorithmic complexity in DecodeFromBytes function in com.upokecenter.cbor Java implementation of Concise Binary Object Representation (CBOR) versions 4.0.0 to 4.5.1 allows an attacker to cause a denial of service by passing a …
- CVE-2024-21909HIGHCVSS 7.5EG 7.52024-01-03
PeterO.Cbor versions 4.0.0 through 4.5.0 are vulnerable to a denial of service vulnerability. An attacker may trigger the denial of service condition by providing crafted data to the DecodeFromBytes or other decoding mechanisms in Peter…
- CVE-2023-46136HIGHCVSS 7.5EG 7.52023-10-25
Werkzeug is a comprehensive WSGI web application library. In versions on the 3.x branch prior to 3.0.1 and on the 2.x branch prior to 2.3.8, if an upload of a file that starts with CR or LF and then is followed by megabytes of data without…
- CVE-2023-38285HIGHCVSS 7.5EG 7.52023-07-26
Trustwave ModSecurity 3.x before 3.0.10 has Inefficient Algorithmic Complexity.
- CVE-2022-45061HIGHCVSS 7.5EG 7.52022-11-09
An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder c…
- CVE-2022-40188HIGHCVSS 7.5EG 7.52022-09-23
Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity. During an attack, an authoritative server must return large NS sets or address sets.
- CVE-2022-39209HIGHCVSS 7.5EG 7.52022-09-15
cmark-gfm is GitHub's fork of cmark, a CommonMark parsing and rendering library and program in C. In versions prior to 0.29.0.gfm.6 a polynomial time complexity issue in cmark-gfm's autolink extension may lead to unbounded resource exhaust…
- CVE-2022-22153HIGHCVSS 7.5EG 7.52022-01-19
An Insufficient Algorithmic Complexity combined with an Allocation of Resources Without Limits or Throttling vulnerability in the flow processing daemon (flowd) of Juniper Networks Junos OS on SRX Series and MX Series with SPC3 allows an u…
- CVE-2021-33582HIGHCVSS 7.5EG 7.52021-09-01
Cyrus IMAP before 3.4.2 allows remote attackers to cause a denial of service (multiple-minute daemon hang) via input that is mishandled during hash-table interaction. Because there are many insertions into a single bucket, strcmp becomes s…
- CVE-2019-19331HIGHCVSS 7.5EG 7.52019-12-16
knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization. DNS replies with very many resource records might be processed very inefficiently, in extreme cases taking even several CPU seconds for eac…
- CVE-2018-12558HIGHCVSS 7.5EG 7.52018-06-20
The parse() method in the Email::Address module through 1.909 for Perl is vulnerable to Algorithmic complexity on specially prepared input, leading to Denial of Service. Prepared special input that caused this problem contained 30 form-fie…
- CVE-2017-11343HIGHCVSS 7.5EG 7.52017-07-17
Due to an incomplete fix for CVE-2012-6125, all versions of CHICKEN Scheme up to and including 4.12.0 are vulnerable to an algorithmic complexity attack. An attacker can provide crafted input which, when inserted into the symbol table, wil…
- CVE-2016-10396HIGHCVSS 7.5EG 7.52017-07-06
The racoon daemon in IPsec-Tools 0.8.2 contains a remotely exploitable computational-complexity attack when parsing and storing ISAKMP fragments. The implementation permits a remote attacker to exhaust computational resources on the remote…
- CVE-2022-36021HIGHCVSS 5.5EG 7.42023-03-01
Redis is an in-memory database that persists on disk. Authenticated users can use string matching commands (like `SCAN` or `KEYS`) with a specially crafted pattern to trigger a denial-of-service attack on Redis, causing it to hang and cons…
- CVE-2026-67419HIGHCVSS 7.1EG 7.12026-09-25
RabbitMQ is a messaging and streaming broker. Prior to 4.3.5, an authenticated user who can bind a queue to a topic exchange and publish to it can use consecutive # segments in a binding key to make both topic matchers revisit the same tri…
- CVE-2026-45822MEDIUMCVSS 6.6EG 6.62026-06-30
decode-uri-component through 0.4.1 is vulnerable to denial of service. The decode() function splits input on '%' producing N tokens and calls decodeComponents(), exhibiting super-linear parsing time: 200 '%ab' tokens takes approximately 0.…
- CVE-2026-107287MEDIUMCVSS 6.5EG 6.52026-10-08
Pydantic AI is a Python agent framework for building applications and workflows with Generative AI. From 1.77.0 until 1.107.7 and 2.52.0, the local web_fetch_tool and the WebFetch local fallback can consume excessive CPU and memory during …
- CVE-2026-107583MEDIUMCVSS 6.5EG 6.52026-10-08
Inefficient algorithmic complexity in the webmail's message view of the REST API in Progressive Robot hMailServer 6.3.2 through 6.3.5 allows a remote unauthenticated attacker to make the webmail, the administration console and the REST API…
- CVE-2026-107582MEDIUMCVSS 6.5EG 6.52026-10-08
Inefficient algorithmic complexity in the REST API (6.3.3 through 6.3.5) and the IMAP PREVIEW response (6.2.22 through 6.3.5) of Progressive Robot hMailServer allows a remote unauthenticated attacker to make the webmail, the administration…
- CVE-2026-107581MEDIUMCVSS 6.5EG 6.52026-10-08
Progressive Robot hMailServer 6.0.0 through 6.3.5 processes several IMAP commands from a signed-in account in time quadratic in the command's length or in the number of elements it names, and can be made to hold memory out of proportion to…
- CVE-2026-107580MEDIUMCVSS 6.5EG 6.52026-10-08
Inefficient algorithmic complexity in the decoding of message header fields in Progressive Robot hMailServer 6.0.0 through 6.3.5 allows a remote unauthenticated attacker to make the IMAP, SMTP and POP3 services, or the webmail, unavailable…
- CVE-2026-76271MEDIUMCVSS 6.5EG 6.52026-10-07
In Splunk Enterprise versions below 10.4.3, 10.2.7, and 10.0.10, a low-privileged user that does not hold the "admin" or "power" Splunk roles could cause a denial of service against a Representational State Transfer (REST) API endpoint in …
- CVE-2026-95112MEDIUMCVSS 6.5EG 6.52026-10-06
When processing issue and comment bodies, Gitea scanned the entire preceding text for action keywords such as "closes" or "fixes" once per Markdown link, giving processing time quadratic in the input size. An authenticated user able to sub…
- CVE-2026-72663MEDIUMCVSS 6.5EG 6.52026-08-13
Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-153). A specially crafted, deeply nested expression submitted to a Kibana TSVB visualization is evaluated with a worst-…
- CVE-2026-13064MEDIUMCVSS 6.5EG 6.52026-07-22
Certain query operations involving deeply nested $jsonSchema constructs can trigger disproportionate CPU consumption in affected MongoDB deployments, potentially leading to resource exhaustion. The resulting CPU-bound operation cannot be i…
- CVE-2026-35599MEDIUMCVSS 6.5EG 6.52026-04-10
Vikunja is an open-source self-hosted task management platform. Prior to 2.3.0, the addRepeatIntervalToTime function uses an O(n) loop that advances a date by the task's RepeatAfter duration until it exceeds the current time. By creating a…
- CVE-2026-33033MEDIUMCVSS 6.5EG 6.52026-04-07
An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `MultiPartParser` allows remote attackers to degrade performance by submitting multipart uploads with `Content-Transfer-Encoding: base64` including exce…
- CVE-2026-33123MEDIUMCVSS 6.5EG 6.52026-03-20
pypdf is a free and open-source pure-python PDF library. Versions prior to 6.9.1 allow an attacker to craft a malicious PDF which leads to long runtimes and/or large memory usage. Exploitation requires accessing an array-based stream with …
Map vulnerabilities like CWE-407 to your infrastructure
EchelonGraph correlates every CVE — across CWE-407 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →