Lucene search

K
osvGoogleOSV:USN-5138-1
HistoryNov 10, 2021 - 10:09 p.m.

python-py vulnerability

2021-11-1022:09:54
Google
osv.dev
11
vulnerability
python-py
regular expression
catastrophic backtracing
denial of service
malicious input
software

AI Score

6.5

Confidence

High

EPSS

0.003

Percentile

70.3%

The py.path.svnwc component of py (aka python-py) through v1.9.0 contains
a regular expression with an ambiguous subpattern that is susceptible to
catastrophic backtracing. This could be used by attackers to cause a compute-time
denial of service attack by supplying malicious input to the blame functionality.