- Home
- Resources
- Cheat Sheets
- Regexp Security Cheatsheet
Regexp Security Cheatsheet
A comprehensive repository documenting security vulnerabilities in regular expressions used by Web Application Firewalls, including bypass examples and SAST tools for vulnerability identification.

Regexp Security Cheatsheet
A comprehensive repository documenting security vulnerabilities in regular expressions used by Web Application Firewalls, including bypass examples and SAST tools for vulnerability identification.
Go Beyond the Directory. Track the Entire Market.
Monitor competitor funding, hiring signals, product launches, and market movements across the whole industry.
Regexp Security Cheatsheet Description
A repository that catalogs security vulnerabilities found in regular expressions commonly implemented in Web Application Firewalls (WAFs). The resource provides detailed documentation of bypass techniques and examples that demonstrate how attackers can circumvent regex-based security controls. The cheatsheet focuses on high-severity issues and includes practical examples of regex patterns that can be exploited. It serves as a reference for security professionals to understand common weaknesses in regex implementations used for input validation and filtering. The repository includes SAST (Static Application Security Testing) tools designed to identify vulnerabilities in custom regular expressions. These tools help developers and security teams analyze their regex patterns for potential security flaws before deployment. Originally presented at BlackHat USA 2016, the resource has been maintained and updated to reflect current bypass techniques and vulnerability patterns. It provides both offensive and defensive perspectives on regex security, making it valuable for penetration testers, security researchers, and developers working on WAF implementations.
Regexp Security Cheatsheet FAQ
Common questions about Regexp Security Cheatsheet including features, pricing, alternatives, and user reviews.
Regexp Security Cheatsheet is A comprehensive repository documenting security vulnerabilities in regular expressions used by Web Application Firewalls, including bypass examples and SAST tools for vulnerability identification.. It is a Resources solution designed to help security teams with Vulnerability Analysis, Security Research, Static Analysis.
FEATURED
Fix-first AppSec powered by agentic remediation, covering SCA, SAST & secrets.
Cybercrime intelligence tools for searching compromised credentials from infostealers
Password manager with end-to-end encryption and identity protection features
Fractional CISO services for B2B companies to build security programs
POPULAR
Real-time OSINT monitoring for leaked credentials, data, and infrastructure
A threat intelligence aggregation service that consolidates and summarizes security updates from multiple sources to provide comprehensive cybersecurity situational awareness.
AI security assurance platform for red-teaming, guardrails & compliance
TRENDING CATEGORIES
Stay Updated with Mandos Brief
Get strategic cybersecurity insights in your inbox