CVE-2024-3651: Internationalized Domain Names in Applications (IDNA) vulnerable to denial of service from specially crafted inputs to idna.encode
(updated )
A specially crafted argument to the idna.encode() function could consume significant resources. This may lead to a denial-of-service.
References
- github.com/advisories/GHSA-jjg7-2v4v-x38h
- github.com/kjd/idna
- github.com/kjd/idna/commit/1d365e17e10d72d0b7876316fc7b9ca0eebdd38d
- github.com/kjd/idna/security/advisories/GHSA-jjg7-2v4v-x38h
- github.com/pypa/advisory-database/tree/main/vulns/idna/PYSEC-2024-60.yaml
- huntr.com/bounties/93d78d07-d791-4b39-a845-cbfabc44aadb
- lists.debian.org/debian-lts-announce/2024/05/msg00006.html
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/4YQUPYH3SVZ5GFF2CDQ55FCM575AZTF2
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/F2S5E23N6E52S46KGNYTDFB75LOC4N4D
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/S5IDLLD2IKSIVRBSLB34WTSYGLMWUFWF
- lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ULSC7HBJKXB3BZV367WM5BR6DFEC4Z43
- nvd.nist.gov/vuln/detail/CVE-2024-3651
Code Behaviors & Features
Detect and mitigate CVE-2024-3651 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →