CVE-2022-42964

MEDIUM

pymatgen - Denial of Service via GaussianInput.from_string ReDoS

Title source: llm
STIX 2.1

Description

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the pymatgen PyPI package, when an attacker is able to supply arbitrary input to the GaussianInput.from_string method

References (1)

Core 1
Core References

Scores

CVSS v3 5.9
EPSS 0.0082
EPSS Percentile 52.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-1333
Status published
Products (2)
materialsvirtuallab/pymatgen
pypi/pymatgen 0PyPI
Published Nov 09, 2022
Tracked Since Feb 18, 2026