CVE-2024-3772: Regular expression denial of service in Pydantic < 2.4.0
Last updated 12 November 2024
Other sources
Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string.
— NVD
Regular expression denial of service in Pydantic < 2.4.0, < 1.10.13 allows remote attackers to cause denial of service via a crafted email string.
— GitHub
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3772?
CVE-2024-3772 is classified as a denial of service vulnerability in Pydantic.
How do I fix CVE-2024-3772?
To fix CVE-2024-3772, upgrade Pydantic to version 1.10.13 or 2.4.0.
Which versions of Pydantic are affected by CVE-2024-3772?
Pydantic versions before 1.10.13 and between 2.0.0 and 2.4.0 are affected by CVE-2024-3772.
Can CVE-2024-3772 be exploited remotely?
Yes, CVE-2024-3772 can be exploited remotely through a crafted email string.
Is there a known workaround for CVE-2024-3772?
There are no specific workarounds recommended for CVE-2024-3772 other than upgrading to the fixed versions.