7.5
CVSSv3

CVE-2023-33290

Published: 12/06/2023 Updated: 21/06/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

The git-url-parse crate up to and including 0.4.4 for Rust allows Regular Expression Denial of Service (ReDos) via a crafted URL to normalize_url in lib.rs, a similar issue to CVE-2023-32758 (Python).

Vulnerable Product Search on Vulmon Subscribe to Product

git-url-parse project git-url-parse