High severity7.5NVD Advisory· Published Jun 21, 2023· Updated Jun 17, 2026
CVE-2023-33289
CVE-2023-33289
Description
The urlnorm crate through 0.1.4 for Rust allows Regular Expression Denial of Service (ReDos) via a crafted URL to lib.rs. NOTE: the Supplier disputes this, taking the position that "Slow printing of URLs is not a CVE."
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
urlnormcrates.io | <= 0.1.4 | — |
Affected products
3- urlnorm/urlnormdescription
Patches
Vulnerability mechanics
References
5- gist.github.com/6en6ar/b118888dc739e8979038f24c8ac33611nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-fqhp-rhm6-8rrjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-33289ghsaADVISORY
- lib.rs/crates/urlnormnvdProductWEB
- news.ycombinator.com/itemnvdWEB
News mentions
0No linked articles in our index yet.