CWE-407: Inefficient Algorithmic Complexity
Also known as: Quadratic Complexity
An algorithm in a product has an inefficient worst-case computational complexity that may be detrimental to system performance and can be triggered by an attacker, typically using crafted manipulations that ensure that the worst case is being reached.
Last updated
Overview
CWE-407 (Inefficient Algorithmic Complexity) is a class-level software weakness catalogued by MITRE in the Common Weakness Enumeration (CWE). It describes a recurring type of mistake that can lead to exploitable security vulnerabilities.
Real-world CVEs
116 recorded CVEs are caused by CWE-407 (Inefficient Algorithmic Complexity). The highest-severity and most recent are shown first. 75 new CWE-407 CVEs have been recorded so far in 2026 (18 in 2025).
- CVE-2024-43485
.NET and Visual Studio Denial of Service Vulnerability
High · CVSS 8.8 · EPSS 87th2024-10-08 - CVE-2024-43484
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
High · CVSS 8.8 · EPSS 86th2024-10-08 - CVE-2024-43483
.NET, .NET Framework, and Visual Studio Denial of Service Vulnerability
High · CVSS 8.8 · EPSS 86th2024-10-08