VulnerabilityModified
CVE-2023-33289
The urlnorm crate through 0.1.4 for Rust allows Regular Expression Denial of Service (ReDos) via a crafted URL to lib.rs.
HIGH 7.5EPSS 1.20%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.20%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The urlnorm crate through 0.1.4 for Rust allows Regular Expression Denial of Service (ReDos) via a crafted URL to lib.rs. NOTE: the Supplier disputes this, taking the position that "Slow printing of URLs is not a CVE."
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.20% probability · 66th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-1333
- Affected
- urlnorm project/urlnorm
- Source
- cve@mitre.org
References
- https://gist.github.com/6en6ar/b118888dc739e8979038f24c8ac33611Exploit, Third Party Advisory
- https://github.com/progscrape/urlnormProduct
- https://lib.rs/crates/urlnormProduct
- https://news.ycombinator.com/item?id=40435263
- https://gist.github.com/6en6ar/b118888dc739e8979038f24c8ac33611Exploit, Third Party Advisory
- https://github.com/progscrape/urlnormProduct
- https://lib.rs/crates/urlnormProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.