ThreatCluster

ReDoS Vulnerabilities in Microsoft Products Announced

First seen 18 Feb 2026, 15:24 UTC Api.Msrc.Microsoft 79% similarity 36

Article Content

Browse articles
ThreatCluster

Two vulnerabilities related to Regular Expression Denial of Service (ReDoS) have been reported. CVE-2020-28493, published on February 1, 2021, and CVE-2021-42836, published on October 22, 2021, both allow attackers to exploit regular expressions in software, potentially leading to denial of service. Affected products include those utilizing these specific CVEs.

ThreatCluster AI

Timeline

2021-02-01
CVE-2020-28493 published
2021-10-22
CVE-2021-42836 published
2026-02-18
Information published about both CVEs

Community

Browse all →

Tracked Entities in This Story