py vulnerable to Regular Expression Denial of Service
High severity
GitHub Reviewed
Published
Apr 20, 2021
to the GitHub Advisory Database
•
Updated Oct 21, 2024
Description
Published by the National Vulnerability Database
Dec 9, 2020
Reviewed
Apr 9, 2021
Published to the GitHub Advisory Database
Apr 20, 2021
Last updated
Oct 21, 2024
A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service attack by supplying malicious input to the blame functionality.
References