CVE-2024-25885

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Oct 8, 2024
Updated: Oct 10, 2024
CWE ID 1333

Summary

CVE-2024-25885 is a newly disclosed vulnerability affecting the getcolor function in utils.py of xhtml2pdf version 0.2.13. Maliciously crafted strings can trigger a Regular Expression Denial of Service (ReDoS) attack, leading to excessive consumption of system resources and potential denial of service conditions. This issue can be exploited by attackers to cause the targeted system to become unresponsive, disrupting normal operations until the affected component is properly secured or replaced.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share