mechanize, a library for automatically interacting with HTTP web servers, contains a regular expression that is vulnerable to regular expression denial of service (ReDoS) prior to version 0.4.6. If a web server responds in a malicious way, then mechanize could crash. Version 0.4.6 has a patch for the issue.
Metrics
Affected Vendors & Products
References
History
Mon, 22 Dec 2025 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 10 Mar 2025 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2023-01-17T00:00:00.000Z
Updated: 2025-12-22T01:32:19.985Z
Reserved: 2021-05-12T00:00:00.000Z
Link: CVE-2021-32837
Updated: 2025-12-22T01:32:19.985Z
Status : Modified
Published: 2023-01-17T22:15:10.533
Modified: 2025-12-22T02:16:01.123
Link: CVE-2021-32837
No data.