Skip to main content

Inefficient Regular Expression Complexity

CVE-2024-3772

Severity Medium
Score 5.9/10

Summary

Regular expression denial of service in Pydanic allows remote attackers to cause denial of service via a crafted email string. This issue affects pydantic versions prior to 1.10.13 and 2.x prior to 2.4.0.

  • HIGH
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • HIGH

CWE-1333 - Inefficient Regular Expression Complexity

The product uses a regular expression with an inefficient, possibly exponential worst-case computational complexity that consumes excessive CPU cycles.

Advisory Timeline

  • Published