Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-53016.json
JSON Data
https://api.test.osv.dev/v1/vulns/AZL-53016
Upstream
Published
2024-11-12T22:15:14Z
Modified
2026-04-01T05:17:56.191559Z
Summary
CVE-2024-11168 affecting package python3 for versions less than 3.9.19-7
Details

The urllib.parse.urlsplit() and urlparse() functions improperly validated bracketed hosts ([]), allowing hosts that weren't IPv6 or IPvFuture. This behavior was not conformant to RFC 3986 and potentially enabled SSRF if a URL is processed by more than one URL parser.

References

Affected packages

Azure Linux:2 / python3

Package

Name
python3
Purl
pkg:rpm/azure-linux/python3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.9.19-7

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-53016.json"