Kjd/Idna Library Vulnerability Affects Version 3.6, Leading to Denial of Service
CVE-2024-3651
Key Information:
Badges
What is CVE-2024-3651?
A vulnerability has been identified in the kjd/idna library, particularly affecting the functionality of the idna.encode() method in version 3.6. This problem stems from the method's inadequate handling of specially crafted input strings, which can lead to significant computational overhead. When triggered, this can cause the function to exhibit quadratic complexity in processing, resulting in a potential denial of service scenario. The vulnerability allows an attacker to provide maliciously designed input that substantially prolongs the processing time, thereby exploiting the system's resources.
Affected Version(s)
kjd/idna < 3.7
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V3.1
CVSS V3.0
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
