Launch Week Day 1: Announcing Security Design Review
MEDIUM 5.9 PyPI

pymatgen is vulnerable to Regular Expression Denial of Service (ReDoS)

GHSA-5jqp-885w-xj32 · CVE-2022-42964

Published · Modified

Description

An exponential ReDoS (Regular Expression Denial of Service) can be triggered in the pymatgen PyPI package, when an attacker is able to supply arbitrary input to the GaussianInput.from_string method.

Ready to move

Start Securing

Free, no credit card | First findings in minutes