{"id":"CVE-2023-46402","aliases":["GHSA-3f2q-6294-fmq5"],"title":"Inefficient Regular Expression Complexity in git-urls","summary":"Inefficient Regular Expression Complexity in git-urls","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","vendor":"whilp","product":"github.com/whilp/git-urls","ecosystem":"go","affected":["github.com/whilp/git-urls <= 1.0.1"],"published":"2023-11-18","updated":"2026-09-10","sourceUpdated":"2026-09-10T03:50:04.009495687Z","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-3f2q-6294-fmq5","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-46402"},{"url":"https://gist.github.com/6en6ar/7c2424c93e7fbf2b6fc44e7fb9acb95d"},{"url":"https://github.com/whilp/git-urls"}],"tags":["osv","go"],"epss":0.0085,"epssPercentile":0.56169,"ingestedAt":"2026-09-12T03:13:01.749Z","slug":"CVE-2023-46402","body":"## Overview\n\ngit-urls version 1.0.1 is vulnerable to ReDOS (Regular Expression Denial of Service) in Go package.\n\n## Affected packages\n\n- `github.com/whilp/git-urls <= 1.0.1`\n\n## Remediation\n\nRefer to the advisory for the patched release.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}