{"api_version":"1","generated_at":"2026-07-23T12:59:31+00:00","cve":"CVE-2023-32758","urls":{"html":"https://cve.report/CVE-2023-32758","api":"https://cve.report/api/cve/CVE-2023-32758.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2023-32758","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2023-32758"},"summary":{"title":"CVE-2023-32758","description":"giturlparse (aka git-url-parse) through 1.2.2, as used in Semgrep 1.5.2 through 1.24.1, is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing untrusted URLs. This might be relevant if Semgrep is analyzing an untrusted package (for example, to check whether it accesses any Git repository at an http:// URL), and that package's author placed a ReDoS attack payload in a URL used by the package.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2023-05-15 04:15:00","updated_at":"2023-06-09 19:15:00"},"problem_types":["CWE-1333"],"metrics":[],"references":[{"url":"https://github.com/returntocorp/semgrep/pull/7955","name":"https://github.com/returntocorp/semgrep/pull/7955","refsource":"MISC","tags":[],"title":"Fix other source of slowness in git URL parser + limit URL length to 1024 by mjambon · Pull Request #7955 · returntocorp/semgrep · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/coala/git-url-parse/blob/master/giturlparse/parser.py#L53","name":"https://github.com/coala/git-url-parse/blob/master/giturlparse/parser.py#L53","refsource":"MISC","tags":[],"title":"git-url-parse/parser.py at master · coala/git-url-parse · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://pypi.org/project/git-url-parse","name":"https://pypi.org/project/git-url-parse","refsource":"MISC","tags":[],"title":"git-url-parse · PyPI","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/returntocorp/semgrep/pull/7943","name":"https://github.com/returntocorp/semgrep/pull/7943","refsource":"MISC","tags":[],"title":"Fix for ReDoS vulnerability by mjambon · Pull Request #7943 · returntocorp/semgrep · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://github.com/returntocorp/semgrep/pull/7611","name":"https://github.com/returntocorp/semgrep/pull/7611","refsource":"MISC","tags":[],"title":"fix(cli): git URL parsing for subgroups by brandonspark · Pull Request #7611 · returntocorp/semgrep · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2023-32758","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-32758","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2023","cve_id":"32758","vulnerable":"1","versionEndIncluding":"1.2.2","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"coala","cpe5":"git-url-parse","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2023","cve_id":"32758","vulnerable":"-1","versionEndIncluding":"1.21.0","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"semgrep","cpe5":"semgrep","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2023-32758","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"giturlparse (aka git-url-parse) through 1.2.2, as used in Semgrep 1.5.2 through 1.24.1, is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing untrusted URLs. This might be relevant if Semgrep is analyzing an untrusted package (for example, to check whether it accesses any Git repository at an http:// URL), and that package's author placed a ReDoS attack payload in a URL used by the package."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://github.com/coala/git-url-parse/blob/master/giturlparse/parser.py#L53","refsource":"MISC","name":"https://github.com/coala/git-url-parse/blob/master/giturlparse/parser.py#L53"},{"url":"https://pypi.org/project/git-url-parse","refsource":"MISC","name":"https://pypi.org/project/git-url-parse"},{"url":"https://github.com/returntocorp/semgrep/pull/7611","refsource":"MISC","name":"https://github.com/returntocorp/semgrep/pull/7611"},{"refsource":"MISC","name":"https://github.com/returntocorp/semgrep/pull/7955","url":"https://github.com/returntocorp/semgrep/pull/7955"},{"refsource":"MISC","name":"https://github.com/returntocorp/semgrep/pull/7943","url":"https://github.com/returntocorp/semgrep/pull/7943"}]}},"nvd":{"publishedDate":"2023-05-15 04:15:00","lastModifiedDate":"2023-06-09 19:15:00","problem_types":["CWE-1333"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:coala:git-url-parse:*:*:*:*:*:*:*:*","versionEndIncluding":"1.2.2","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:a:semgrep:semgrep:*:*:*:*:*:*:*:*","versionEndIncluding":"1.21.0","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":null,"notes":[]}}}