dparse is a parser for Python dependency files. dparse in versions before 0.5.2 contain a regular expression that is vulnerable to a Regular Expression Denial of Service. All the users parsing index server URLs with dparse are impacted by this vulnerability. A patch has been applied in version `0.5.2`, all the users are advised to upgrade to `0.5.2` as soon as possible. Users unable to upgrade should avoid passing index server URLs in the source file to be parsed.

Project Subscriptions

Vendors Products
Dependency Parser Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2022-0096 dparse is a parser for Python dependency files. dparse in versions before 0.5.2 contain a regular expression that is vulnerable to a Regular Expression Denial of Service. All the users parsing index server URLs with dparse are impacted by this vulnerability. A patch has been applied in version `0.5.2`, all the users are advised to upgrade to `0.5.2` as soon as possible. Users unable to upgrade should avoid passing index server URLs in the source file to be parsed.
Github GHSA Github GHSA GHSA-8fg9-p83m-x5pq ReDoS issue in dparse
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 23 Apr 2025 17:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2025-04-23T16:52:14.285Z

Reserved: 2022-09-02T00:00:00.000Z

Link: CVE-2022-39280

cve-icon Vulnrichment

Updated: 2024-08-03T12:00:43.472Z

cve-icon NVD

Status : Modified

Published: 2022-10-06T18:16:18.007

Modified: 2024-11-21T07:17:56.850

Link: CVE-2022-39280

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses