Low severity3.7OSV Advisory· Published Nov 12, 2024· Updated Apr 15, 2026
CVE-2024-11168
CVE-2024-11168
Description
The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts ([]), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and potentially enabled SSRF if a URL is processed by more than one URL parser.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
139v0.9.8, v0.9.9, v1.0.1, …+ 1 more
- (no CPE)range: v0.9.8, v0.9.9, v1.0.1, …
- (no CPE)
- osv-coords137 versionspkg:apk/chainguard/python-3.10pkg:apk/chainguard/python-3.10-basepkg:apk/chainguard/python-3.10-base-devpkg:apk/chainguard/python-3.10-devpkg:apk/chainguard/python-3.10-docpkg:apk/chainguard/python-3.9pkg:apk/chainguard/python-3.9-basepkg:apk/chainguard/python-3.9-base-devpkg:apk/chainguard/python-3.9-defaultpkg:apk/chainguard/python-3.9-devpkg:apk/chainguard/python-3.9-docpkg:apk/wolfi/python-3.10pkg:apk/wolfi/python-3.10-basepkg:apk/wolfi/python-3.10-base-devpkg:apk/wolfi/python-3.10-devpkg:apk/wolfi/python-3.10-docpkg:bitnami/libpythonpkg:bitnami/pythonpkg:bitnami/python-minpkg:rpm/almalinux/platform-pythonpkg:rpm/almalinux/platform-python-debugpkg:rpm/almalinux/platform-python-develpkg:rpm/almalinux/python3pkg:rpm/almalinux/python39pkg:rpm/almalinux/python39-attrspkg:rpm/almalinux/python39-cffipkg:rpm/almalinux/python39-chardetpkg:rpm/almalinux/python39-cryptographypkg:rpm/almalinux/python39-Cythonpkg:rpm/almalinux/python39-debugpkg:rpm/almalinux/python39-develpkg:rpm/almalinux/python39-idlepkg:rpm/almalinux/python39-idnapkg:rpm/almalinux/python39-iniconfigpkg:rpm/almalinux/python39-libspkg:rpm/almalinux/python39-lxmlpkg:rpm/almalinux/python39-mod_wsgipkg:rpm/almalinux/python39-more-itertoolspkg:rpm/almalinux/python39-numpypkg:rpm/almalinux/python39-numpy-docpkg:rpm/almalinux/python39-numpy-f2pypkg:rpm/almalinux/python39-packagingpkg:rpm/almalinux/python39-pippkg:rpm/almalinux/python39-pip-wheelpkg:rpm/almalinux/python39-pluggypkg:rpm/almalinux/python39-plypkg:rpm/almalinux/python39-psutilpkg:rpm/almalinux/python39-psycopg2pkg:rpm/almalinux/python39-psycopg2-docpkg:rpm/almalinux/python39-psycopg2-testspkg:rpm/almalinux/python39-pypkg:rpm/almalinux/python39-pybind11pkg:rpm/almalinux/python39-pybind11-develpkg:rpm/almalinux/python39-pycparserpkg:rpm/almalinux/python39-PyMySQLpkg:rpm/almalinux/python39-pyparsingpkg:rpm/almalinux/python39-pysockspkg:rpm/almalinux/python39-pytestpkg:rpm/almalinux/python39-pyyamlpkg:rpm/almalinux/python39-requestspkg:rpm/almalinux/python39-rpm-macrospkg:rpm/almalinux/python39-scipypkg:rpm/almalinux/python39-setuptoolspkg:rpm/almalinux/python39-setuptools-wheelpkg:rpm/almalinux/python39-sixpkg:rpm/almalinux/python39-testpkg:rpm/almalinux/python39-tkinterpkg:rpm/almalinux/python39-tomlpkg:rpm/almalinux/python39-urllib3pkg:rpm/almalinux/python39-wcwidthpkg:rpm/almalinux/python39-wheelpkg:rpm/almalinux/python39-wheel-wheelpkg:rpm/almalinux/python3-debugpkg:rpm/almalinux/python3-develpkg:rpm/almalinux/python3-idlepkg:rpm/almalinux/python3-libspkg:rpm/almalinux/python3-testpkg:rpm/almalinux/python3-tkinterpkg:rpm/almalinux/python-unversioned-commandpkg:rpm/opensuse/python310-core&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/python310-core&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/python310&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/python310&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/python310&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python310-documentation&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/python310-documentation&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/python39-core&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/python39-core&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/python39&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/python39&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/python39&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python39-documentation&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/python39-documentation&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/python3-core&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/python3-core&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/python3-core&distro=openSUSE%20Leap%20Micro%205.5pkg:rpm/opensuse/python3&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/python3&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/python3&distro=openSUSE%20Leap%20Micro%205.5pkg:rpm/opensuse/python3-documentation&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/python3-documentation&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/python-base&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/python-base&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/python&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/python&distro=openSUSE%20Leap%2015.6pkg:rpm/opensuse/python&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/python-doc&distro=openSUSE%20Leap%2015.5pkg:rpm/opensuse/python-doc&distro=openSUSE%20Leap%2015.6pkg:rpm/suse/python36-core&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5pkg:rpm/suse/python36&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5pkg:rpm/suse/python39-core&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2015%20SP5pkg:rpm/suse/python39&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Legacy%2015%20SP5pkg:rpm/suse/python3-base&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5pkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20Micro%205.5pkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP5pkg:rpm/suse/python3-core&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP6pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Micro%205.1pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Micro%205.2pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Micro%205.3pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Micro%205.4pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Micro%205.5pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP5pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP6pkg:rpm/suse/python3&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5pkg:rpm/suse/python-base&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP5pkg:rpm/suse/python-base&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP6pkg:rpm/suse/python-base&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5pkg:rpm/suse/python&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP5pkg:rpm/suse/python&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Package%20Hub%2015%20SP6pkg:rpm/suse/python&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5pkg:rpm/suse/python-doc&distro=SUSE%20Linux%20Enterprise%20Server%20LTSS%20Extended%20Security%2012%20SP5
< 3.10.16-r0+ 136 more
- (no CPE)range: < 3.10.16-r0
- (no CPE)range: < 3.10.16-r0
- (no CPE)range: < 3.10.16-r0
- (no CPE)range: < 3.10.16-r0
- (no CPE)range: < 3.10.16-r0
- (no CPE)range: < 3.9.21-r0
- (no CPE)range: < 3.9.21-r0
- (no CPE)range: < 3.9.21-r0
- (no CPE)range: < 3.9.21-r0
- (no CPE)range: < 3.9.21-r0
- (no CPE)range: < 3.9.21-r0
- (no CPE)range: < 3.10.16-r0
- (no CPE)range: < 3.10.16-r0
- (no CPE)range: < 3.10.16-r0
- (no CPE)range: < 3.10.16-r0
- (no CPE)range: < 3.10.16-r0
- (no CPE)range: < 3.9.21
- (no CPE)range: < 3.9.21
- (no CPE)range: < 3.9.21
- (no CPE)range: < 3.6.8-69.el8_10.alma.1
- (no CPE)range: < 3.6.8-69.el8_10.alma.1
- (no CPE)range: < 3.6.8-69.el8_10.alma.1
- (no CPE)range: < 3.9.21-1.el9_5
- (no CPE)range: < 3.9.25-2.module_el8.10.0+4083+53cad1fb
- (no CPE)range: < 20.3.0-2.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 1.14.3-2.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 3.0.4-19.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 3.3.1-3.module_el8.10.0+3765+2f9a457d
- (no CPE)range: < 0.29.21-5.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 3.9.25-2.module_el8.10.0+4083+53cad1fb
- (no CPE)range: < 3.9.25-2.module_el8.10.0+4083+53cad1fb
- (no CPE)range: < 3.9.25-2.module_el8.10.0+4083+53cad1fb
- (no CPE)range: < 2.10-4.module_el8.10.0+3849+a48d89aa
- (no CPE)range: < 1.1.1-2.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 3.9.25-2.module_el8.10.0+4083+53cad1fb
- (no CPE)range: < 4.6.5-1.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 4.7.1-7.module_el8.10.0+3989+a618fe15.1
- (no CPE)range: < 8.5.0-2.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 1.19.4-3.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 1.19.4-3.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 1.19.4-3.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 20.4-4.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 20.2.4-9.module_el8.10.0+3765+2f9a457d
- (no CPE)range: < 20.2.4-9.module_el8.10.0+3765+2f9a457d
- (no CPE)range: < 0.13.1-3.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 3.11-10.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 5.8.0-4.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 2.8.6-3.module_el8.10.0+3765+2f9a457d
- (no CPE)range: < 2.8.6-3.module_el8.10.0+3765+2f9a457d
- (no CPE)range: < 2.8.6-3.module_el8.10.0+3765+2f9a457d
- (no CPE)range: < 1.10.0-1.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 2.7.1-1.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 2.7.1-1.module_el8.6.0+3248+c431e88c
- (no CPE)range: < 2.20-3.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 0.10.1-2.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 2.4.7-5.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 1.7.1-4.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 6.0.2-2.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 5.4.1-1.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 2.25.0-3.module_el8.9.0+3634+fb2a896c
- (no CPE)range: < 3.9.25-2.module_el8.10.0+4083+53cad1fb
- (no CPE)range: < 1.5.4-5.module_el8.9.0+3634+fb2a896c
- (no CPE)range: < 50.3.2-7.module_el8.10.0+4040+9207bbc0
- (no CPE)range: < 50.3.2-7.module_el8.10.0+4040+9207bbc0
- (no CPE)range: < 1.15.0-3.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 3.9.25-2.module_el8.10.0+4083+53cad1fb
- (no CPE)range: < 3.9.25-2.module_el8.10.0+4083+53cad1fb
- (no CPE)range: < 0.10.1-5.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 1.25.10-5.module_el8.10.0+3765+2f9a457d
- (no CPE)range: < 0.2.5-3.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 1:0.35.1-4.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 1:0.35.1-4.module_el8.6.0+2780+a40f65e1
- (no CPE)range: < 3.9.21-1.el9_5
- (no CPE)range: < 3.9.21-1.el9_5
- (no CPE)range: < 3.6.8-69.el8_10.alma.1
- (no CPE)range: < 3.6.8-69.el8_10.alma.1
- (no CPE)range: < 3.6.8-69.el8_10.alma.1
- (no CPE)range: < 3.6.8-69.el8_10.alma.1
- (no CPE)range: < 3.9.21-1.el9_5
- (no CPE)range: < 3.10.15-150400.4.63.1
- (no CPE)range: < 3.10.15-150400.4.63.1
- (no CPE)range: < 3.10.15-150400.4.63.1
- (no CPE)range: < 3.10.15-150400.4.63.1
- (no CPE)range: < 3.10.15-5.1
- (no CPE)range: < 3.10.15-150400.4.63.1
- (no CPE)range: < 3.10.15-150400.4.63.1
- (no CPE)range: < 3.9.20-150300.4.58.1
- (no CPE)range: < 3.9.20-150300.4.58.1
- (no CPE)range: < 3.9.20-150300.4.58.1
- (no CPE)range: < 3.9.20-150300.4.58.1
- (no CPE)range: < 3.9.20-6.1
- (no CPE)range: < 3.9.20-150300.4.58.1
- (no CPE)range: < 3.9.20-150300.4.58.1
- (no CPE)range: < 3.6.15-150300.10.78.1
- (no CPE)range: < 3.6.15-150300.10.78.1
- (no CPE)range: < 3.6.15-150300.10.78.1
- (no CPE)range: < 3.6.15-150300.10.78.1
- (no CPE)range: < 3.6.15-150300.10.78.1
- (no CPE)range: < 3.6.15-150300.10.78.1
- (no CPE)range: < 3.6.15-150300.10.78.1
- (no CPE)range: < 3.6.15-150300.10.78.1
- (no CPE)range: < 2.7.18-150000.68.1
- (no CPE)range: < 2.7.18-150000.68.1
- (no CPE)range: < 2.7.18-150000.68.1
- (no CPE)range: < 2.7.18-150000.68.1
- (no CPE)range: < 2.7.18-51.1
- (no CPE)range: < 2.7.18-150000.68.1
- (no CPE)range: < 2.7.18-150000.68.1
- (no CPE)range: < 3.6.15-73.1
- (no CPE)range: < 3.6.15-73.1
- (no CPE)range: < 3.9.20-150300.4.58.1
- (no CPE)range: < 3.9.20-150300.4.58.1
- (no CPE)range: < 3.4.10-25.145.1
- (no CPE)range: < 3.6.15-150000.3.167.1
- (no CPE)range: < 3.6.15-150300.10.78.1
- (no CPE)range: < 3.6.15-150300.10.78.1
- (no CPE)range: < 3.6.15-150300.10.78.1
- (no CPE)range: < 3.6.15-150300.10.78.1
- (no CPE)range: < 3.6.15-150300.10.78.1
- (no CPE)range: < 3.6.15-150300.10.78.1
- (no CPE)range: < 3.6.15-150300.10.78.1
- (no CPE)range: < 3.6.15-150300.10.78.1
- (no CPE)range: < 3.6.15-150000.3.167.1
- (no CPE)range: < 3.6.15-150300.10.78.1
- (no CPE)range: < 3.6.15-150300.10.78.1
- (no CPE)range: < 3.6.15-150300.10.78.1
- (no CPE)range: < 3.6.15-150300.10.78.1
- (no CPE)range: < 3.6.15-150300.10.78.1
- (no CPE)range: < 3.6.15-150300.10.78.1
- (no CPE)range: < 3.4.10-25.145.1
- (no CPE)range: < 2.7.18-150000.68.1
- (no CPE)range: < 2.7.18-150000.68.1
- (no CPE)range: < 2.7.18-33.38.1
- (no CPE)range: < 2.7.18-150000.68.1
- (no CPE)range: < 2.7.18-150000.68.1
- (no CPE)range: < 2.7.18-33.38.1
- (no CPE)range: < 2.7.18-33.38.1
Patches
Vulnerability mechanics
References
9- github.com/python/cpython/commit/29f348e232e82938ba2165843c448c2b291504c5nvd
- github.com/python/cpython/commit/634ded45545ce8cbd6fd5d49785613dd7fa9b89envd
- github.com/python/cpython/commit/b2171a2fd41416cf68afd67460578631d755a550nvd
- github.com/python/cpython/commit/ddca2953191c67a12b1f19d6bca41016c6ae7132nvd
- github.com/python/cpython/issues/103848nvd
- github.com/python/cpython/pull/103849nvd
- lists.debian.org/debian-lts-announce/2024/12/msg00000.htmlnvd
- mail.python.org/archives/list/security-announce@python.org/thread/XPWB6XVZ5G5KGEI63M4AWLIEUF5BPH4T/nvd
- security.netapp.com/advisory/ntap-20250411-0004/nvd
News mentions
0No linked articles in our index yet.