No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 03 Jun 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A weakness has been identified in johnhuang316 code-index-mcp up to 2.14.0. Affected is the function is_safe_regex_pattern of the component search_code_advanced. Executing a manipulation of the argument regex can lead to inefficient regular expression complexity. It is possible to launch the attack remotely. The exploit has been made available to the public and could be used for attacks. Upgrading to version 2.14.1 is able to address this issue. This patch is called 25bc02fac74051ddae15ce79e952f00211b1ea6b. Upgrading the affected component is recommended. | |
| Title | johnhuang316 code-index-mcp search_code_advanced is_safe_regex_pattern redos | |
| First Time appeared |
Johnhuang316
Johnhuang316 code-index-mcp |
|
| Weaknesses | CWE-1333 CWE-400 |
|
| CPEs | cpe:2.3:a:johnhuang316:code-index-mcp:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Johnhuang316
Johnhuang316 code-index-mcp |
|
| References |
|
|
| Metrics |
cvssV2_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-06-02T23:45:12.046Z
Reserved: 2026-06-02T15:43:28.477Z
Link: CVE-2026-10692
No data.
Status : Received
Published: 2026-06-03T00:16:31.143
Modified: 2026-06-03T00:16:31.143
Link: CVE-2026-10692
No data.
OpenCVE Enrichment
Updated: 2026-06-03T03:45:23Z