CVE-2017-18361: Pylonsproject Colander
High severity, CVSS 7.5. EPSS: 2% chance of exploitation in the next 30 days.
In Pylons Colander through 1.6, the URL validator allows an attacker to potentially cause an infinite loop thereby causing a denial of service via an unclosed parenthesis.
Affected products
- Pylonsproject Colander: up to and including 1.6
Published 2019-02-01. Last modified 2026-06-17.