Back

HIGH

py: ReDoS in py library when used with subversion

Published Oct 16, 2022

Description

The py library through 1.11.0 for Python allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a Subversion repository with crafted info data, because the InfoSvnCommand argument is mishandled. Note: This has been disputed by multiple third parties as not being reproduceable and they argue this is not a valid vulnerability.

Affected products

Remediation

Red Hat statement

This has been disputed by multiple parties, including the upstream maintainers, as not being reproducible or a valid vulnerability.

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 16, 2022
Updated May 14, 2025
Reserved Oct 16, 2022
CISA Vulnrichment
Updated May 14, 2025
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Oct 16, 2022
ENISA EUVD
Assigner mitre
Published Oct 16, 2022
Updated May 14, 2025
Exploited since n/a
EUVD-2022-0207