High severity7.5NVD Advisory· Published Jun 12, 2023· Updated Jun 17, 2026
CVE-2023-33290
CVE-2023-33290
Description
The git-url-parse crate through 0.4.4 for Rust allows Regular Expression Denial of Service (ReDos) via a crafted URL to normalize_url in lib.rs, a similar issue to CVE-2023-32758 (Python).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
git-url-parsecrates.io | <= 0.4.4 | — |
Affected products
3- cpe:2.3:a:git-url-parse_project:git-url-parse:*:*:*:*:*:rust:*:*Range: <=0.4.4
- git-url-parse/git-url-parsedescription
Patches
Vulnerability mechanics
References
5- github.com/tjtelan/git-url-parse-rs/issues/51nvdExploitIssue TrackingThird Party AdvisoryWEB
- github.com/advisories/GHSA-qfh9-8p57-mjjjghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2023-33290ghsaADVISORY
- github.com/tjtelan/git-url-parse-rs/blob/main/src/lib.rsghsaWEB
- lib.rs/crates/git-url-parsenvdProduct
News mentions
0No linked articles in our index yet.