CVE-2023-33289: Urlnorm Project Urlnorm
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
The urlnorm crate through 0.1.4 for Rust allows Regular Expression Denial of Service (ReDos) via a crafted URL to lib.rs. NOTE: the Supplier disputes this, taking the position that "Slow printing of URLs is not a CVE."
Affected products
- Urlnorm Project Urlnorm: up to and including 0.1.4
Published 2023-06-21. Last modified 2026-06-17.