cbcvebase.
CVE-2025-0938
published 2025-01-31

CVE-2025-0938: The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to…

PriorityP335medium6.3CVSS 4.0
AVNACHATPPRNUINVCNVILVANSCNSILSANEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
1.50%
71.4th percentile
The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianpypy3< pypy3 7.3.5+dfsg-2+deb11u5 (bullseye)pypy3 7.3.5+dfsg-2+deb11u5 (bullseye)
debianpython3.11< pypy3 7.3.5+dfsg-2+deb11u5 (bullseye)pypy3 7.3.5+dfsg-2+deb11u5 (bullseye)
debianpython3.13< pypy3 7.3.5+dfsg-2+deb11u5 (bullseye)pypy3 7.3.5+dfsg-2+deb11u5 (bullseye)
debianpython3.9< pypy3 7.3.5+dfsg-2+deb11u5 (bullseye)pypy3 7.3.5+dfsg-2+deb11u5 (bullseye)
python_software_foundationcpython< 3.10.173.10.17
python_software_foundationcpython>= 3.11.0 < 3.11.123.11.12
python_software_foundationcpython>= 3.12.0 < 3.12.93.12.9
python_software_foundationcpython>= 3.13.0 < 3.13.23.13.2
python_software_foundationcpython>= 3.14.0a1 < 3.14.0a53.14.0a5

CVSS provenance

nvdv4.06.3MEDIUMCVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv6.3MEDIUM
vendor_debian6.3MEDIUM
vendor_redhat6.3MEDIUM
vendor_ubuntu3.7LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.