Duplicate Advisory: ReDos vulnerability of XMLFeedSpider
High severity
GitHub Reviewed
Published
Feb 28, 2024
to the GitHub Advisory Database
•
Updated Apr 16, 2024
Withdrawn
This advisory was withdrawn on Apr 16, 2024
Description
Published by the National Vulnerability Database
Feb 28, 2024
Published to the GitHub Advisory Database
Feb 28, 2024
Reviewed
Apr 16, 2024
Withdrawn
Apr 16, 2024
Last updated
Apr 16, 2024
Duplicate Advisory
This advisory has been withdrawn because it is a duplicate of GHSA-cc65-xxvf-f7r9. This link is maintained to preserve external references.
Original Description
Parts of the Scrapy API were found to be vulnerable to a ReDoS attack. Handling a malicious response could cause extreme CPU and memory usage during the parsing of its content, due to the use of vulnerable regular expressions for that parsing.
References