CVE-2024-3772
published 2024-04-15CVE-2024-3772: Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string.
PriorityP434high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
0.95%
57.8th percentile
Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pydantic | < pydantic 1.10.13-0.1 (forky) | pydantic 1.10.13-0.1 (forky) |
| fedoraproject | fedora | — | — |
| pydantic | pydantic | < 1.10.13 | 1.10.13 |
| pydantic | pydantic | >= 0 < 1.10.13-0.1 | 1.10.13-0.1 |
| pydantic | pydantic | >= 0 < 1.10.13-0.1 | 1.10.13-0.1 |
| pydantic | pydantic | >= 0 < 1.10.13 | 1.10.13 |
| pydantic | pydantic | >= 1.0 < 1.10.13 | 1.10.13 |
| pydantic | pydantic | >= 2.0 < 2.4.0 | 2.4.0 |
| pydantic | pydantic | >= 2.0.0 < 2.4.0 | 2.4.0 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Pydantic regular expression denial of service
ghsa·2024-04-15
CVE-2024-3772 [MEDIUM] CWE-1333 Pydantic regular expression denial of service
Pydantic regular expression denial of service
Regular expression denial of service in Pydantic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string.
OSV
Pydantic regular expression denial of service
osv·2024-04-15
CVE-2024-3772 [MEDIUM] Pydantic regular expression denial of service
Pydantic regular expression denial of service
Regular expression denial of service in Pydantic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string.
OSV
CVE-2024-3772: Regular expression denial of service in Pydanic < 2
osv·2024-04-15·CVSS 7.5
CVE-2024-3772 [HIGH] CVE-2024-3772: Regular expression denial of service in Pydanic < 2
Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string.
Ubuntu
Pydantic vulnerability
vendor_ubuntu·2024-11-12
CVE-2024-3772 Pydantic vulnerability
Title: Pydantic vulnerability
Summary: Pydantic could be made to crash if it received specially crafted
input.
It was discovered that Pydantic incorrectly handled certain regular
expressions. A remote attacker could possibly use this issue to cause a
denial of service via a crafted email string.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
python-pydantic: regular expression denial of service via crafted email string
vendor_redhat·2024-04-15·CVSS 5.9
CVE-2024-3772 [MEDIUM] CWE-1333 python-pydantic: regular expression denial of service via crafted email string
python-pydantic: regular expression denial of service via crafted email string
Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string.
A flaw was found in Pydantic, where it did not properly validate regular expressions containing white spaces. This flaw allows remote users to cause a denial of service attack via a crafted email string.
Mitigation: Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
Debian
CVE-2024-3772: pydantic - Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote...
vendor_debian·2024·CVSS 5.9
CVE-2024-3772 [MEDIUM] CVE-2024-3772: pydantic - Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote...
Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 1.10.13-0.1)
sid: resolved (fixed in 1.10.13-0.1)
trixie: resolved (fixed in 1.10.13-0.1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2024-45341 golang: crypto/x509: crypto/x509: usage of IPv6 zone IDs can bypass URI name constraints
bugzilla·2025-01-23·CVSS 6.1
CVE-2024-45341 [MEDIUM] CVE-2024-45341 golang: crypto/x509: crypto/x509: usage of IPv6 zone IDs can bypass URI name constraints
CVE-2024-45341 golang: crypto/x509: crypto/x509: usage of IPv6 zone IDs can bypass URI name constraints
A certificate with a URI which has a IPv6 address with a zone ID may incorrectly satisfy a URI name constraint that applies to the certificate chain.
Certificates containing URIs are not permitted in the web PKI, so this only affects users of private PKIs which make use of URIs.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 8
Via RHSA-2025:3772 https://access.redhat.com/errata/RHSA-2025:3772
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2025:7466 https://access.redhat.com/errata/RHSA-2025:7466
Bugzilla
CVE-2024-3772 python-pydantic: regular expression denial of service via crafted email string
bugzilla·2024-04-15·CVSS 7.5
CVE-2024-3772 [HIGH] CVE-2024-3772 python-pydantic: regular expression denial of service via crafted email string
CVE-2024-3772 python-pydantic: regular expression denial of service via crafted email string
Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string.
Upstream PR:
https://github.com/pydantic/pydantic/pull/7360
Discussion:
Created python-pydantic tracking bugs for this issue:
Affects: fedora-38 [bug 2275108]
---
This issue has been addressed in the following products:
Red Hat Ansible Automation Platform 2.4 for RHEL 9
Red Hat Ansible Automation Platform 2.4 for RHEL 8
Via RHSA-2024:3781 https://access.redhat.com/errata/RHSA-2024:3781
https://github.com/pydantic/pydantic/pull/7360https://lists.fedoraproject.org/archives/list/[email protected]/message/6JBZLMSH4GAZOVBMT2JUO2LXHY7M2ALI/https://github.com/pydantic/pydantic/pull/7360https://lists.fedoraproject.org/archives/list/[email protected]/message/6JBZLMSH4GAZOVBMT2JUO2LXHY7M2ALI/
2024-04-15
Published