CWE · MITRE source
CWE-1333Inefficient Regular Expression Complexity
The product uses a regular expression with a worst-case computational complexity that is inefficient and possibly exponential.
Last updated: 04 July 2026 00:28 UTC
Cumulative inbound coverage
How completely the frameworks we cross-walk collectively cover this — the verdict is the strongest single mapping (overlapping partials are not summed); breadth shows the corroboration behind it.
Collective: full · 2 mapping(s) from 2 framework(s): ATT&CK 1 (full) · CAPEC 1 (partial)
NIST 800-53 r5 controls that address this weakness (0)AI
| Control | Title | Family | Why it addresses this CWE |
|---|---|---|---|
| No NIST controls proposed yet. | |||
MITRE ATT&CK techniques this weakness enables
Our own two-way CWE↔ATT&CK cross-walk — a direct mapping with no public source (the CWE→CAPEC→ATT&CK chain leaves most top weaknesses, incl. XSS and SQLi, mapped to nothing). Drafted by Grok and spot-checked by Claude Opus 4.8.
Direction: ← other covers this;
→ this covers other (F/M/P = full / mostly /
partial).
Top CVEs of this weakness type, ranked by Risk Priority
| CVE | Risk | CVSS | EPSS | Published |
|---|---|---|---|---|
CVE-2023-29486 | 7.0 | 9.8 | 0.0103 | 2023-12-21 |
CVE-2023-29487 | 7.0 | 9.1 | 0.0066 | 2023-12-21 |
CVE-2026-35458 | 7.0 | 9.8 | 0.0050 | 2026-04-07 |
CVE-2026-52778 UPD | 7.0 | 9.8 | 0.0056 | 2026-06-08 |
CVE-2022-24713 | 6.0 | 7.5 | 0.1446 | 2022-03-08 |
CVE-2021-32837 | 6.0 | 7.5 | 0.2866 | 2023-01-17 |
CVE-2023-3364 | 6.0 | 7.5 | 0.4467 | 2023-08-02 |
CVE-2024-25126 UPD | 6.0 | 5.3 | 0.3538 | 2024-02-29 |
CVE-2024-2829 | 6.0 | 7.5 | 0.2596 | 2024-04-25 |
CVE-2024-2651 | 6.0 | 6.5 | 0.3330 | 2024-05-14 |
CVE-2024-8124 | 6.0 | 7.5 | 0.3958 | 2024-09-12 |
CVE-2015-8315 | 5.5 | 7.5 | 0.0677 | 2017-01-23 |
CVE-2015-8854 | 5.5 | 7.5 | 0.0430 | 2017-01-23 |
CVE-2019-12041 | 5.5 | 7.5 | 0.0132 | 2019-05-13 |
CVE-2021-26813 | 5.5 | 7.5 | 0.0238 | 2021-03-03 |
CVE-2021-28092 | 5.5 | 7.5 | 0.0217 | 2021-03-12 |
CVE-2021-27291 | 5.5 | 7.5 | 0.0383 | 2021-03-17 |
CVE-2021-33502 | 5.5 | 7.5 | 0.0170 | 2021-05-24 |
CVE-2020-1920 | 5.5 | 7.5 | 0.0136 | 2021-06-01 |
CVE-2021-3649 | 5.5 | 7.5 | 0.0122 | 2021-07-16 |
CVE-2021-3749 | 5.5 | 7.5 | 0.0852 | 2021-08-31 |
CVE-2021-3777 | 5.5 | 7.5 | 0.0126 | 2021-09-15 |
CVE-2021-3794 | 5.5 | 7.5 | 0.0118 | 2021-09-15 |
CVE-2021-3795 | 5.5 | 7.5 | 0.0141 | 2021-09-15 |
CVE-2021-3803 | 5.5 | 7.5 | 0.0201 | 2021-09-17 |