VYPR

Git URL Parse

by Coala

CVEs (1)

  • CVE-2023-32758HigMay 15, 2023
    risk 0.42cvss 7.5epss 0.01

    giturlparse (aka git-url-parse) through 1.2.2, as used in Semgrep 1.5.2 through 1.24.1, is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing untrusted URLs. This might be relevant if Semgrep is analyzing an untrusted package (for example, to check whether it…