Headline
GHSA-2p9h-ccw7-33gf: cleo is vulnerable to Regular Expression Denial of Service (ReDoS)
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the cleo PyPI package, when an attacker is able to supply arbitrary input to the Table.set_rows method.
cleo is vulnerable to Regular Expression Denial of Service (ReDoS)
Moderate severity GitHub Reviewed Published Nov 10, 2022 • Updated Nov 10, 2022
Related news
CVE-2022-42966: cleo ReDoS | XRAY-257186
An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the cleo PyPI package, when an attacker is able to supply arbitrary input to the Table.set_rows method