Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36306
HistoryJul 09, 2022 - 9:00 p.m.

Regular Expression Denial Of Service (ReDoS)

2022-07-0921:00:18
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
12
py3-mistune vulnerability redos attack asterisk_emphasis crash system

EPSS

0.001

Percentile

46.7%

py3-mistune is vulnerable to regular expression denial of service. An attacker is able crash the system by injecting a maliciously crafted string into ASTERISK_EMPHASIS.