CVE-2025-0938

The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers.

Open
LOW (0.4)
  • logo

    System detected CVE-2025-0938

  • logo

    System updated the risk assessment from 0 to 0.42

    System recalculated raw risk assessment

  • logo

    System updated the risk assessment from 0 to 0.42

    System recalculated raw risk assessment

  • logo

    System fixed CVE-2025-0938

  • logo

    System fixed CVE-2025-0938

  • logo

    System detected CVE-2025-0938 with a risk of 0.42

Add a comment

Mark as False Positive
Last calculated at:

Affected component

debian/python3.11

Installed version:
3.11.2-6
Fixed in:
no patch available

Management decisions across the organization

Copyright © 2025 L3montree GmbH and the DevGuard Contributors. All rights reserved. Version 2ab7b793efd72421aea8c3a994ac60202bf1b3a5