CVE-2017-18361: Pylonsproject Colander

High severity, CVSS 7.5. EPSS: 2% chance of exploitation in the next 30 days.

In Pylons Colander through 1.6, the URL validator allows an attacker to potentially cause an infinite loop thereby causing a denial of service via an unclosed parenthesis.

Affected products

Published 2019-02-01. Last modified 2026-06-17.