{"id":"CVE-2023-4138","aliases":["GHSA-wwrg-2w5j-grvx","PYSEC-2026-1863"],"title":"RDiffWeb vulnerable to Allocation of Resources Without Limits or Throttling","summary":"RDiffWeb vulnerable to Allocation of Resources Without Limits or Throttling","severity":"medium","cvss":4.2,"cvssVector":"CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L","vendor":"rdiffweb","product":"rdiffweb","ecosystem":"pip","affected":["rdiffweb < 2.8.1"],"patched":["rdiffweb 2.8.1"],"published":"2023-08-03","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-wwrg-2w5j-grvx","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-4138"},{"url":"https://github.com/ikus060/rdiffweb/commit/feef0d7b11d86aed29bf98c21526088117964d85"},{"url":"https://github.com/ikus060/rdiffweb"},{"url":"https://huntr.dev/bounties/1b1fa915-d588-4bb1-9e82-6a6be79befed"}],"tags":["osv","pip"],"epss":0.00448,"epssPercentile":0.38192,"ingestedAt":"2026-07-08T18:25:53.924Z","slug":"CVE-2023-4138","body":"## Overview\n\nAllocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.0.\n\n## Affected packages\n\n- `rdiffweb < 2.8.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `rdiffweb 2.8.1`","depth":"sunlit","depthScore":23,"depthScoreParts":{"impact":23.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}