PT-2025-4103 · Python+10 · Python+10
CVSS v3.1
6.8
Medium
| Vector | AV:N/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Python versions prior to 3.11.12
Description
The Python standard library functions
urllib.parse.urlsplit() and urlparse() accepted domain names containing square brackets, which violates RFC 3986. According to the specification, square brackets should only be used as delimiters for IPv6 and IPvFuture hosts in URLs. This inconsistency can lead to differential parsing between the Python URL parser and other parsers that strictly comply with the specification.Recommendations
Update Python to version 3.11.12.
Exploit
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Almalinux
Astra Linux
Centos
Debian
Linuxmint
Python
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu