A flaw has been found in kokke tiny-regex-c up to f2632c6d9ed25272987471cdb8b70395c2460bdb. This vulnerability affects the function matchstar of the file re.c of the component Pattern Handler. This manipulation causes inefficient regular expression complexity. The attack is restricted to local execution. The exploit has been published and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.
History

Mon, 08 Jun 2026 03:15:00 +0000

Type Values Removed Values Added
Description A flaw has been found in kokke tiny-regex-c up to f2632c6d9ed25272987471cdb8b70395c2460bdb. This vulnerability affects the function matchstar of the file re.c of the component Pattern Handler. This manipulation causes inefficient regular expression complexity. The attack is restricted to local execution. The exploit has been published and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet.
Title kokke tiny-regex-c Pattern re.c matchstar redos
First Time appeared Kokke
Kokke tiny-regex-c
Weaknesses CWE-1333
CWE-400
CPEs cpe:2.3:a:kokke:tiny-regex-c:*:*:*:*:*:*:*:*
Vendors & Products Kokke
Kokke tiny-regex-c
References
Metrics cvssV2_0

{'score': 1.7, 'vector': 'AV:L/AC:L/Au:S/C:N/I:N/A:P/E:POC/RL:ND/RC:UR'}

cvssV3_0

{'score': 3.3, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L/E:P/RL:X/RC:R'}

cvssV4_0

{'score': 4.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-06-08T02:00:16.513Z

Reserved: 2026-06-07T09:42:50.401Z

Link: CVE-2026-11478

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-08T03:16:19.997

Modified: 2026-06-08T03:16:19.997

Link: CVE-2026-11478

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-08T05:00:14Z