{"id":"GHSA-qfh9-8p57-mjjj","summary":"git-url-parse crate vulnerable to Regular Expression Denial of Service","details":"The git-url-parse crate through 0.4.4 for Rust allows Regular Expression Denial of Service (ReDos) via a crafted URL to `normalize_url` in `lib.rs`, a similar issue to CVE-2023-32758 (Python).","aliases":["CVE-2023-33290"],"modified":"2023-11-08T04:12:40.550704Z","published":"2023-06-12T15:30:28Z","database_specific":{"severity":"LOW","github_reviewed":true,"github_reviewed_at":"2023-06-12T18:55:56Z","nvd_published_at":"2023-06-12T13:15:10Z","cwe_ids":["CWE-1333"]},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-33290"},{"type":"WEB","url":"https://github.com/tjtelan/git-url-parse-rs/issues/51"},{"type":"PACKAGE","url":"https://github.com/tjtelan/git-url-parse-rs"},{"type":"WEB","url":"https://github.com/tjtelan/git-url-parse-rs/blob/main/src/lib.rs#L396"}],"affected":[{"package":{"name":"git-url-parse","ecosystem":"crates.io","purl":"pkg:cargo/git-url-parse"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.4.4"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/06/GHSA-qfh9-8p57-mjjj/GHSA-qfh9-8p57-mjjj.json"}}],"schema_version":"1.9.0"}