CWE-185: Incorrect Regular Expression
The product specifies a regular expression in a way that causes data to be improperly matched or compared.
Overview
When the regular expression is used in protection mechanisms such as filtering or validation, this may allow an attacker to bypass the intended restrictions on the incoming data.
Real-world CVEs
20 recorded CVEs are caused by CWE-185 (Incorrect Regular Expression). The highest-severity and most recent are shown first. 9 new CWE-185 CVEs have been recorded so far in 2026 (1 in 2025).