CVE-2024-25885
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Oct 8, 2024
Updated: Oct 10, 2024
CWE ID 1333
Summary
CVE-2024-25885 is a newly disclosed vulnerability affecting the getcolor function in utils.py of xhtml2pdf version 0.2.13. Maliciously crafted strings can trigger a Regular Expression Denial of Service (ReDoS) attack, leading to excessive consumption of system resources and potential denial of service conditions. This issue can be exploited by attackers to cause the targeted system to become unresponsive, disrupting normal operations until the affected component is properly secured or replaced.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.