CVE-2025-0938

Updated: 2025-02-21 12:19:31.3772

Description:

The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x NONE 0.0
CVSS Version 3.x MEDIUM 6.8

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

AlmaLinux 9.2 ESU python3.11 3.11.2 6.8 MEDIUM Released CLSA-2025:1741126677 2025-03-05 21:52:15
AlmaLinux 9.2 ESU python3 3.9.16 6.8 MEDIUM Released CLSA-2025:1742919946 2025-03-26 03:28:56
CentOS 8.4 ELS python3 3.6.8 6.8 MEDIUM Released CLSA-2025:1741635599 2025-03-10 22:57:54
CentOS 8.4 ELS python2 2.7.18 6.8 MEDIUM Released CLSA-2026:1767629333 2026-01-05 20:08:48
CentOS 8.5 ELS python2 2.7.18 6.8 MEDIUM Released CLSA-2026:1767800687 2026-01-07 20:15:50
CentOS 8.5 ELS python3 3.6.8 6.8 MEDIUM Released CLSA-2025:1741635940 2025-03-10 22:57:55
CentOS Stream 8 ELS python2 2.7.18 6.8 MEDIUM Released CLSA-2026:1767800092 2026-01-07 20:15:52
Ubuntu 16.04 ELS python3.5 3.5.2 6.8 MEDIUM Released CLSA-2025:1742379028 2025-03-20 03:52:33
Ubuntu 18.04 ELS python3.6 3.6.9-1 6.8 MEDIUM Released CLSA-2025:1750780647 2025-06-25 02:57:22