CVE-2022-42966

MEDIUM

cleo < 2.0.0 - Regular Expression Denial of Service via Table.set_rows Method

Title source: llm
STIX 2.1

Description

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the cleo PyPI package, when an attacker is able to supply arbitrary input to the Table.set_rows method

References (1)

Core 1
Core References

Scores

CVSS v3 5.9
EPSS 0.0091
EPSS Percentile 55.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-1333
Status published
Products (2)
pypi/cleo 0 - 2.0.0PyPI
python-poetry/cleo < 2.0.0
Published Nov 09, 2022
Tracked Since Feb 18, 2026