CVE-2024-3651

Source
https://cve.org/CVERecord?id=CVE-2024-3651
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-3651.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-3651
Aliases
Downstream
ALPINE (1)
AZL (5)
BELL (1)
CGA (166)
CLSA (5)
DEBIAN (1)
MGASA (1)
MINI (2)
OESA (6)
openSUSE (2)
RHSA (7)
RLSA (2)
ROOT (1)
SUSE (8)
UBUNTU (1)
Related
Published
2024-07-07T17:22:10Z
Modified
2026-09-08T18:26:39Z
Severity
  • 6.2 (Medium) CVSS_V3 - CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
Denial of Service via Quadratic Complexity in kjd/idna
Details

A vulnerability was identified in the kjd/idna library, specifically within the idna.encode() function, affecting version 3.6. The issue arises from the function's handling of crafted input strings, which can lead to quadratic complexity and consequently, a denial of service condition. This vulnerability is triggered by a crafted input that causes the idna.encode() function to process the input with considerable computational load, significantly increasing the processing time in a quadratic manner relative to the input size.

Database specific
{
    "cna_assigner":  "@huntr_ai",
    "cwe_ids":  [
        "CWE-1333"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/3xxx/CVE-2024-3651.json"
}
References

Affected packages

Git / github.com/kjd/idna

Affected ranges

Type
GIT
Repo
https://github.com/kjd/idna
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:kjd:internationalized_domain_names_in_applications:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "3.7"
        },
        {
            "introduced":  "0.2"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "CPE_RANGE",
        "REFERENCES"
    ]
}

Affected versions

v0.*
v0.2
v0.3
v0.4
v0.5
v0.6
v0.7
v0.8
v0.9
v1.*
v1.0
v1.1
v2.*
v2.0
v2.1
v2.10
v2.2
v2.3
v2.4
v2.5
v2.6
v2.7
v2.8
v2.9
v3.*
v3.0
v3.1
v3.2
v3.3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-3651.json"