Lucene search

K
osvGoogleOSV:GHSA-G3RQ-G295-4J3M
HistoryMar 19, 2021 - 9:28 p.m.

Regular Expression Denial of Service (ReDoS) in Jinja2

2021-03-1921:28:05
Google
osv.dev
63

0.002 Low

EPSS

Percentile

57.4%

This affects the package jinja2 from 0.0.0 and before 2.11.3. The ReDOS vulnerability of the regex is mainly due to the sub-pattern [a-zA-Z0-9.-]+.[a-zA-Z0-9.-]+ This issue can be mitigated by Markdown to format user content instead of the urlize filter, or by implementing request timeouts and limiting process memory.

Rows per page:
1-10 of 371