{"id":"GHSA-w596-4wvx-j9j6","summary":"Withdrawn Advisory: ReDoS in py library when used with subversion ","details":"### Withdrawn Advisory\nThis advisory has been withdrawn because evidence does not suggest that CVE-2022-42969 is a valid, reproducible vulnerability. This link is maintained to preserve external references.\n\n### Original Description\nThe py library through 1.11.0 for Python allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a Subversion repository with crafted info data, because the InfoSvnCommand argument is mishandled.\n\nThe particular codepath in question is the regular expression at `py._path.svnurl.InfoSvnCommand.lspattern` and is only relevant when dealing with subversion (svn) projects. Notably the codepath is not used in the popular pytest project. The developers of the pytest package have released version `7.2.0` which removes their dependency on `py`. Users of `pytest` seeing alerts relating to this advisory may update to version `7.2.0` of `pytest` to resolve this issue. See https://github.com/pytest-dev/py/issues/287#issuecomment-1290407715 for additional context.","aliases":["CVE-2022-42969"],"modified":"2026-09-10T03:49:46.736589852Z","published":"2022-10-16T12:00:23Z","withdrawn":"2025-08-01T20:34:11Z","database_specific":{"github_reviewed_at":"2022-10-18T18:03:13Z","nvd_published_at":"2022-10-16T06:15:00Z","cwe_ids":["CWE-1333"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-42969"},{"type":"WEB","url":"https://github.com/pytest-dev/py/issues/287"},{"type":"WEB","url":"https://github.com/pytest-dev/py/issues/288"},{"type":"WEB","url":"https://github.com/pytest-dev/pytest/issues/10392"},{"type":"ADVISORY","url":"https://github.com/advisories/GHSA-w596-4wvx-j9j6"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/py/PYSEC-2022-42969.yaml"},{"type":"WEB","url":"https://github.com/pypa/advisory-database/tree/main/vulns/py/PYSEC-2022-43183.yaml"},{"type":"PACKAGE","url":"https://github.com/pytest-dev/py"},{"type":"WEB","url":"https://github.com/pytest-dev/py/blob/cb87a83960523a2367d0f19226a73aed4ce4291d/py/_path/svnurl.py#L316"},{"type":"WEB","url":"https://news.ycombinator.com/item?id=34163710"},{"type":"WEB","url":"https://pypi.org/project/py"}],"affected":[{"package":{"name":"py","ecosystem":"PyPI","purl":"pkg:pypi/py"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"1.11.0"}]}],"versions":["0.8.0-alpha2","0.9.0","0.9.1","0.9.2","1.0.0","1.0.1","1.0.2","1.1.0","1.1.1","1.10.0","1.11.0","1.2.0","1.2.1","1.3.0","1.3.1","1.3.2","1.3.3","1.3.4","1.4.0","1.4.1","1.4.10","1.4.11","1.4.12","1.4.13","1.4.14","1.4.15","1.4.16","1.4.17","1.4.18","1.4.19","1.4.2","1.4.20","1.4.21","1.4.22","1.4.23","1.4.24","1.4.25","1.4.26","1.4.27","1.4.28","1.4.29","1.4.3","1.4.30","1.4.31","1.4.32","1.4.32.dev1","1.4.33","1.4.34","1.4.4","1.4.5","1.4.6","1.4.7","1.4.7.dev3","1.4.8","1.4.9","1.5.1","1.5.2","1.5.3","1.5.4","1.6.0","1.7.0","1.8.0","1.8.1","1.8.2","1.9.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/10/GHSA-w596-4wvx-j9j6/GHSA-w596-4wvx-j9j6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}