MEDIUM4.2
PYSEC-2026-1863
RDiffWeb vulnerable to Allocation of Resources Without Limits or Throttling
Quick fix
PYSEC-2026-1863 — rdiffweb: upgrade to the fixed version with the command below.
pip install --upgrade 'rdiffweb>=2.8.1'Details
Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.8.0.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2023-4138[ADVISORY]
- https://github.com/ikus060/rdiffweb/commit/feef0d7b11d86aed29bf98c21526088117964d85[FIX]
- https://github.com/ikus060/rdiffweb[PACKAGE]
- https://huntr.dev/bounties/1b1fa915-d588-4bb1-9e82-6a6be79befed[WEB]
- https://pypi.org/project/rdiffweb[PACKAGE]
- https://github.com/advisories/GHSA-wwrg-2w5j-grvx[ADVISORY]