Metrics
Affected Vendors & Products
Fri, 14 Mar 2025 10:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Fri, 28 Feb 2025 19:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Tue, 04 Feb 2025 20:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Sat, 01 Feb 2025 02:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Fri, 31 Jan 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Fri, 31 Jan 2025 19:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Fri, 31 Jan 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 31 Jan 2025 18:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers. | |
Title | URL parser allowed square brackets in domain names | |
Weaknesses | CWE-20 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: PSF
Published: 2025-01-31T17:51:35.898Z
Updated: 2025-04-25T17:35:52.426Z
Reserved: 2025-01-31T17:45:10.107Z
Link: CVE-2025-0938

Updated: 2025-03-14T10:03:07.501Z

Status : Awaiting Analysis
Published: 2025-01-31T18:15:38.053
Modified: 2025-03-14T10:15:15.847
Link: CVE-2025-0938
