VYPR

PyPI package

git-url-parse

pkg:pypi/git-url-parse

Vulnerabilities (1)

  • CVE-2023-32758May 15, 2023
    affected <= 1.2.2

    giturlparse (aka git-url-parse) through 1.2.2, as used in Semgrep 1.5.2 through 1.24.1, is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing untrusted URLs. This might be relevant if Semgrep is analyzing an untrusted package (for example, to check whether it a