High severity7.5OSV Advisory· Published Feb 1, 2019· Updated Jun 17, 2026
CVE-2017-18361
CVE-2017-18361
Description
In Pylons Colander through 1.6, the URL validator allows an attacker to potentially cause an infinite loop thereby causing a denial of service via an unclosed parenthesis.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
colanderPyPI | < 1.7.0 | 1.7.0 |
Affected products
3- ghsa-coords2 versions
< 1.7.0+ 1 more
- (no CPE)range: < 1.7.0
- (no CPE)range: < 2.0-1.3
Patches
Vulnerability mechanics
References
6- github.com/Pylons/colander/pull/323nvdPatchThird Party AdvisoryWEB
- github.com/Pylons/colander/issues/290nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-rv95-4wxj-6fqqghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2017-18361ghsaADVISORY
- github.com/Pylons/colander/commit/98805557c10ab5ff3016ed09aa2d48c49b9df40bghsaWEB
- github.com/pypa/advisory-database/tree/main/vulns/colander/PYSEC-2019-167.yamlghsaWEB
News mentions
0No linked articles in our index yet.