CVE-2021-45470

HIGH

Circl Cve-search < 4.1.0 - Denial of Service

Title source: rule
STIX 2.1

Description

lib/DatabaseLayer.py in cve-search before 4.1.0 allows regular expression injection, which can lead to ReDoS (regular expression denial of service) or other impacts.

References (3)

Core 3
Core References
Exploit, Patch, Third Party Advisory x_refsource_misc
https://github.com/cve-search/cve-search/pull/629

Scores

CVSS v3 7.5
EPSS 0.0041
EPSS Percentile 61.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-1333
Status published
Products (1)
circl/cve-search < 4.1.0
Published Dec 23, 2021
Tracked Since Feb 18, 2026