{"id":"CVE-2022-26650","summary":"Apache ShenYu (incubating) Regular expression denial of service","details":"In Apache ShenYui, ShenYu-Bootstrap, RegexPredicateJudge.java uses Pattern.matches(conditionData.getParamValue(), realData) to make judgments, where both parameters are controllable by the user. This can cause an attacker pass in malicious regular expressions and characters causing a resource exhaustion. This issue affects Apache ShenYu (incubating) 2.4.0, 2.4.1 and 2.4.2 and is fixed in 2.4.3.","aliases":["GHSA-cw56-j3fm-7w57"],"modified":"2026-08-27T03:30:19.424419230Z","published":"2022-05-17T08:05:10Z","database_specific":{"cna_assigner":"apache","cwe_ids":["CWE-1333"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/26xxx/CVE-2022-26650.json","unresolved_ranges":[{"extracted_events":[{"fixed":"2.4.3"}],"source":"AFFECTED_FIELD"}]},"references":[{"type":"WEB","url":"https://lists.apache.org/thread/8rp33m3nm4bwtx3qx76mqynth3t3d673"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2022/26xxx/CVE-2022-26650.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-26650"},{"type":"ARTICLE","url":"http://www.openwall.com/lists/oss-security/2022/05/17/3"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/apache/shenyu","events":[{"introduced":"dc841a2720ea0b5a6ca71f1b9c1aa7958d241f16"},{"last_affected":"794a3be979fc8f08e22e40f3ce75644df9c74dad"}],"database_specific":{"extracted_events":[{"introduced":"2.4.0"},{"last_affected":"2.4.0"},{"introduced":"2.4.1"},{"last_affected":"2.4.1"},{"introduced":"2.4.2"},{"last_affected":"2.4.2"}],"source":"CPE_STRING","cpe":["cpe:2.3:a:apache:shenyu:2.4.0:*:*:*:*:*:*:*","cpe:2.3:a:apache:shenyu:2.4.1:*:*:*:*:*:*:*","cpe:2.3:a:apache:shenyu:2.4.2:*:*:*:*:*:*:*"]}}],"versions":["2.4.0","2.4.1","2.4.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2022-26650.json"}}],"schema_version":"1.9.0"}