
We found results for “”
CVE-2025-0938
Good to know:

Date: January 31, 2025
The Python standard library functions "urllib.parse.urlsplit" and "urlparse" accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers.
Severity Score
Related Resources (12)
Severity Score
Weakness Type (CWE)
Improper Input Validation
CWE-20Top Fix

Upgrade Version
Upgrade to version OpenOffice.PDF.Converter - no_fix;Microsoft.NET.Runtime.Emscripten.3.1.7.Python.osx-x64 - no_fix;LostTech.TensorBoard.Python.runtime.win-x64 - no_fix;google-cloud-sdk - 411.0.0;pypy3.6 - no_fix;python - 3.6.1;pythonx86 - 3.6.1;rustpython-pylib - no_fix;Microsoft.NET.Runtime.Emscripten.2.0.21.Python.osx-x64 - no_fix;python - 3.11.1;python - 3.12.9;python - 3.12.0rc2;python - 3.11.6;python - 3.13.2;python - 3.9.14;python - 3.10.7;python - 3.8.14;Microsoft.NET.Runtime.Emscripten.3.1.56.Python.osx-x64 - 9.0.1;Microsoft.NET.Runtime.Emscripten.2.0.12.Python.osx-x64 - no_fix;python3 - 3.8.2;Microsoft.NET.Runtime.Emscripten.2.0.23.Python.osx-x64 - no_fix;Microsoft.NET.Runtime.Emscripten.3.1.12.Python.osx-x64 - no_fix;bleach - no_fix;bleach - 6.0.0;michaeld555/pdf-converter - no_fix;michaeld555/pdf-converter - v1.0.0;Microsoft.NET.Runtime.Emscripten.3.1.34.Python.osx-x64 - no_fix;Microsoft.NET.Runtime.Emscripten.3.1.34.Python.osx-x64 - 8.0.14;firecloud - no_fix;ZioByte.OpenOffice.PDFConverter - no_fix;python-full-x64 - 3.5.1;python-full-x64 - 3.6.1;pypy3.5 - no_fix;python-full-x86 - 3.5.1;python-full-x86 - 3.6.1;pypy3.7 - 7.3.5;rustpython - 0.3.0;ZioByte.OpenOffice - no_fix;michaeld555/nfe-parser - no_fix;Microsoft.NET.Runtime.Emscripten.3.1.34.Python.osx-arm64 - 8.0.14;Microsoft.NET.Runtime.Emscripten.3.1.34.Python.osx-arm64 - no_fix;Microsoft.NET.Runtime.Emscripten.3.1.30.Python.osx-x64 - no_fix;Microsoft.NET.Runtime.Emscripten.3.1.56.Python.osx-arm64 - 9.0.1
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | HIGH |
Privileges Required (PR): | NONE |
User Interaction (UI): | NONE |
Scope (S): | CHANGED |
Confidentiality (C): | NONE |
Integrity (I): | LOW |
Availability (A): | NONE |