{"id":"GHSA-fqhp-rhm6-8rrj","summary":"Withdrawn Advisory: urlnorm vulnerable to Regular Expression Denial of Service","details":"## Withdrawn Advisory\nThis advisory has been withdrawn because the security impact of the slow printing of URLs has been disputed. This link is maintained to preserve external references.\n\n## Original Description\nThe urlnorm crate through 0.1.4 for Rust allows Regular Expression Denial of Service (ReDos) via a crafted URL to lib.rs.","aliases":["CVE-2023-33289"],"modified":"2026-09-10T03:49:54.411848624Z","published":"2023-06-21T21:30:25Z","withdrawn":"2025-03-11T21:55:14Z","database_specific":{"nvd_published_at":"2023-06-21T20:15:10Z","cwe_ids":["CWE-1333"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2023-06-21T21:58:09Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-33289"},{"type":"WEB","url":"https://gist.github.com/6en6ar/b118888dc739e8979038f24c8ac33611"},{"type":"PACKAGE","url":"https://github.com/progscrape/urlnorm"},{"type":"WEB","url":"https://lib.rs/crates/urlnorm"},{"type":"WEB","url":"https://news.ycombinator.com/item?id=40435263"}],"affected":[{"package":{"name":"urlnorm","ecosystem":"crates.io","purl":"pkg:cargo/urlnorm"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.1.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/06/GHSA-fqhp-rhm6-8rrj/GHSA-fqhp-rhm6-8rrj.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"}]}