Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-jj5c-hhrg-vv5h | xhtml2pdf Denial of Service via crafted string |
Thu, 10 Oct 2024 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | xhtml2pdf: From NVD collector | xhtml2pdf: ReDoS via getcolor function in utils.py |
Wed, 09 Oct 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xhtml2pdf
Xhtml2pdf xhtml2pdf |
|
| Weaknesses | CWE-1333 | |
| CPEs | cpe:2.3:a:xhtml2pdf:xhtml2pdf:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xhtml2pdf
Xhtml2pdf xhtml2pdf |
|
| Metrics |
cvssV3_1
|
Wed, 09 Oct 2024 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | xhtml2pdf: From NVD collector | |
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 08 Oct 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue in the getcolor function in utils.py of xhtml2pdf v0.2.13 allows attackers to cause a Regular expression Denial of Service (ReDOS) via supplying a crafted string. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-10-09T14:24:58.398Z
Reserved: 2024-02-12T00:00:00.000Z
Link: CVE-2024-25885
Updated: 2024-10-09T14:11:47.836Z
Status : Deferred
Published: 2024-10-08T18:15:05.423
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-25885
OpenCVE Enrichment
No data.
Github GHSA