The git-url-parse crate through 0.4.4 for Rust allows Regular Expression Denial of Service (ReDos) via a crafted URL to normalize_url
in lib.rs
, a similar issue to CVE-2023-32758 (Python).
{ "nvd_published_at": "2023-06-12T13:15:10Z", "cwe_ids": [ "CWE-1333" ], "severity": "LOW", "github_reviewed": true, "github_reviewed_at": "2023-06-12T18:55:56Z" }