7.4 High
AI Score
Confidence
High
0.007 Low
EPSS
Percentile
79.8%
The py library through 1.11.0 for Python allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a Subversion repository with crafted info data, because the InfoSvnCommand argument is mishandled.
github.com/pytest-dev/py/blob/cb87a83960523a2367d0f19226a73aed4ce4291d/py/_path/svnurl.py
github.com/pytest-dev/py/issues/287
news.ycombinator.com/item?id=34163710
pypi.org/project/py