CVE-2024-11168: Python Software Foundation Cpython
Low severity, CVSS 3.7. EPSS: 0.7% chance of exploitation in the next 30 days.
The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts (`[]`), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and potentially enabled SSRF if a URL is processed by more than one URL parser.
Affected products
- Python Software Foundation Cpython: before 3.9.21 (fixed in 3.9.21); from 3.10.0, before 3.10.16 (fixed in 3.10.16); from 3.11.0, before 3.11.4 (fixed in 3.11.4); from 3.12.0a1, before 3.12.0b1 (fixed in 3.12.0b1); before 3.11.4 (fixed in 3.11.4)
Published 2024-11-12. Last modified 2026-06-17.