Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:31970
HistorySep 06, 2021 - 5:20 a.m.

Regular Expression Denial Of Service (ReDoS)

2021-09-0605:20:55
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
16
pillow vulnerability regex engine

EPSS

0.007

Percentile

79.8%

pillow is vulnerable to regular expression denial of service. The getrgb function accepts user-provided very long color specifier, exhausting regex engine due to excessive CPU consumption and resulting in a Denial of Service.