Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q2q7-5pp4-w6pg

Опубликовано: 01 июн. 2021
Источник: github
Github: Прошло ревью
CVSS4: 8.7
CVSS3: 7.5

Описание

Catastrophic backtracking in URL authority parser when passed URL containing many @ characters

Impact

When provided with a URL containing many @ characters in the authority component the authority regular expression exhibits catastrophic backtracking causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.

Patches

The issue has been fixed in urllib3 v1.26.5.

References

For more information

If you have any questions or comments about this advisory:

Пакеты

Наименование

urllib3

pip
Затронутые версииВерсия исправления

>= 1.25.4, < 1.26.5

1.26.5

EPSS

Процентиль: 74%
0.00863
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
ubuntu
почти 4 года назад

An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.

CVSS3: 7.5
redhat
около 4 лет назад

An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.

CVSS3: 7.5
nvd
почти 4 года назад

An issue was discovered in urllib3 before 1.26.5. When provided with a URL containing many @ characters in the authority component, the authority regular expression exhibits catastrophic backtracking, causing a denial of service if a URL were passed as a parameter or redirected to via an HTTP redirect.

CVSS3: 7.5
msrc
почти 4 года назад

Описание отсутствует

CVSS3: 7.5
debian
почти 4 года назад

An issue was discovered in urllib3 before 1.26.5. When provided with a ...

EPSS

Процентиль: 74%
0.00863
Низкий

8.7 High

CVSS4

7.5 High

CVSS3

Дефекты

CWE-400