QID 997808
Date Published: 2024-03-26
QID 997808: Python (Pip) Security Update for black (GHSA-fj7x-q9j7-g6q6)
Versions of the package black before 24.3.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the lines_with_leading_tabs_expanded function in the strings.py file. An attacker could exploit this vulnerability by crafting a malicious input that causes a denial of service.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-fj7x-q9j7-g6q6 for updates and patch information.
Vendor References
- GHSA-fj7x-q9j7-g6q6 -
github.com/advisories/GHSA-fj7x-q9j7-g6q6
CVEs related to QID 997808
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-fj7x-q9j7-g6q6 | black |
|