CVE-2023-33290: Git-Url-Parse Project Git-Url-Parse

High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.

The git-url-parse crate through 0.4.4 for Rust allows Regular Expression Denial of Service (ReDos) via a crafted URL to normalize_url in lib.rs, a similar issue to CVE-2023-32758 (Python).

Affected products

Published 2023-06-12. Last modified 2026-06-17.