CVE-2023-32758
Estado: ModificadaAlta (7.5)—
giturlparse (aka git-url-parse) through 1.2.2, as used in Semgrep 1.5.2 through 1.24.1, is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing untrusted URLs. This might be relevant if Semgrep is analyzing an untrusted package (for example, to check whether it accesses any Git repository at an http:// URL), and that package's author placed a ReDoS attack payload in a URL used by the package.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.03%
- Percentil entre todas las CVEs puntuadas: 63
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-1333
- CWE-1333
Referencias
- https://github.com/coala/git-url-parse/blob/master/giturlparse/parser.py#L53
- https://github.com/returntocorp/semgrep/pull/7611
- https://github.com/returntocorp/semgrep/pull/7943
- https://github.com/returntocorp/semgrep/pull/7955
- https://pypi.org/project/git-url-parse
- https://github.com/coala/git-url-parse/blob/master/giturlparse/parser.py#L53
- https://github.com/returntocorp/semgrep/pull/7611
- https://github.com/returntocorp/semgrep/pull/7943
- https://github.com/returntocorp/semgrep/pull/7955
- https://pypi.org/project/git-url-parse
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-32758",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-32758",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-01-23T19:35:33.714679Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2023-05-15T04:15:10.330",
"references": [
{
"url": "https://github.com/coala/git-url-parse/blob/master/giturlparse/parser.py#L53",
"tags": [
"Product"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/returntocorp/semgrep/pull/7611",
"tags": [
"Issue Tracking",
"Patch"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/returntocorp/semgrep/pull/7943",
"source": "cve@mitre.org"
},
{
"url": "https://github.com/returntocorp/semgrep/pull/7955",
"source": "cve@mitre.org"
},
{
"url": "https://pypi.org/project/git-url-parse",
"tags": [
"Product"
],
"source": "cve@mitre.org"
},
{
"url": "https://github.com/coala/git-url-parse/blob/master/giturlparse/parser.py#L53",
"tags": [
"Product"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/returntocorp/semgrep/pull/7611",
"tags": [
"Issue Tracking",
"Patch"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/returntocorp/semgrep/pull/7943",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://github.com/returntocorp/semgrep/pull/7955",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://pypi.org/project/git-url-parse",
"tags": [
"Product"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-1333"
}
]
},
{
"type": "Secondary",
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"description": [
{
"lang": "en",
"value": "CWE-1333"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "giturlparse (aka git-url-parse) through 1.2.2, as used in Semgrep 1.5.2 through 1.24.1, is vulnerable to ReDoS (Regular Expression Denial of Service) if parsing untrusted URLs. This might be relevant if Semgrep is analyzing an untrusted package (for example, to check whether it accesses any Git repository at an http:// URL), and that package's author placed a ReDoS attack payload in a URL used by the package."
}
],
"lastModified": "2026-06-17T05:59:32.180",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:coala:git-url-parse:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "83D06CC5-06FA-4F72-BE31-F35ECB2A284F",
"versionEndIncluding": "1.2.2"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:semgrep:semgrep:*:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "2CC52CD5-31F0-4CC6-BB04-04DDB331AD42",
"versionEndIncluding": "1.21.0"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "cve@mitre.org"
}