URL parser allowed square brackets in domain names
Summary
| CVE | CVE-2025-0938 |
|---|---|
| State | PUBLISHED |
| Assigner | PSF |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2025-01-31 18:15:38 UTC |
| Updated | 2026-07-31 14:16:42 UTC |
| Description | The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers. |
Risk And Classification
Primary CVSS: v4.0 6.3 MEDIUM from [email protected]
CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS: 0.015250000 probability, percentile 0.721750000 (date 2026-08-03)
Problem Types: CWE-20 | CWE-20 CWE-20 Improper Input Validation
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 6.3 | MEDIUM | CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 6.3 | MEDIUM | CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
HighAttack Requirements
PresentPrivileges Required
NoneUser Interaction
NoneConfidentiality
NoneIntegrity
LowAvailability
NoneSub Conf.
NoneSub Integrity
LowSub Availability
NoneCVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Python Software Foundation | CPython | affected 3.9.22 python | Not specified |
| CNA | Python Software Foundation | CPython | affected 3.10.0 3.10.17 python | Not specified |
| CNA | Python Software Foundation | CPython | affected 3.11.0 3.11.12 python | Not specified |
| CNA | Python Software Foundation | CPython | affected 3.12.0 3.12.9 python | Not specified |
| CNA | Python Software Foundation | CPython | affected 3.13.0 3.13.2 python | Not specified |
| CNA | Python Software Foundation | CPython | affected 3.14.0a1 3.14.0a5 python | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| github.com/python/cpython/commit/526617ed68cde460236c973e5d0a8bad4de896ba | [email protected] | github.com | |
| github.com/python/cpython/commit/d89a5f6a6e65511a5f6e0618c4c30a7aa5aba56a | [email protected] | github.com | |
| github.com/python/cpython/commit/ff4e5c25666f63544071a6b075ae8b25c98b7a32 | [email protected] | github.com | |
| security.netapp.com/advisory/ntap-20250314-0002 | af854a3a-2127-422b-91ae-364da2661108 | security.netapp.com | |
| lists.debian.org/debian-lts-announce/2025/03/msg00013.html | af854a3a-2127-422b-91ae-364da2661108 | lists.debian.org | |
| github.com/python/cpython/issues/105704 | [email protected] | github.com | |
| github.com/python/cpython/commit/90e526ae67b172ed7c6c56e7edad36263b0f9403 | [email protected] | github.com | |
| github.com/python/cpython/commit/b8b4b713c5f8ec0958c7ef8d29d6711889bc94ab | [email protected] | github.com | |
| github.com/python/cpython/commit/a7084f6075c9595ba60119ce8c62f1496f50c568 | [email protected] | github.com | |
| github.com/python/cpython/pull/129418 | [email protected] | github.com | |
| mail.python.org/archives/list/[email protected]/thread/K4EUG6EKV6J... | [email protected] | mail.python.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.