affected: - package: ecosystem: PyPI name: rdiffweb purl: pkg:pypi/rdiffweb ranges: - events: - introduced: '0' - fixed: b62c479ff6979563c7c23e7182942bc4f460a2c7 repo: https://github.com/ikus060/rdiffweb type: GIT - events: - introduced: '0' - fixed: 2.4.10 type: ECOSYSTEM versions: - 0.10.0 - 0.10.2 - 0.10.3 - 0.10.4 - 0.10.5 - 0.10.6 - 0.10.7 - 0.10.8 - 0.10.9 - 0.9.2.dev1 - 0.9.3 - 0.9.4 - 0.9.5 - 1.0.0 - 1.0.0a1 - 1.0.0a2 - 1.0.0a3 - 1.0.0a4 - 1.0.1 - 1.0.2 - 1.0.3 - 1.1.0 - 1.2.0 - 1.2.1 - 1.2.2 - 1.3.0 - 1.3.1 - 1.3.1b1 - 1.3.1b2 - 1.3.2 - 1.4.0 - 1.4.0b1 - 1.4.0b2 - 1.4.0b3 - 1.4.0b4 - 1.4.0b5 - 1.4.1b1 - 1.4.1b2 - 1.4.1b3 - 1.5.0 - 1.5.1b1 - 1.5.1b2 - 1.6.0b1 - 2.0.1b2 - 2.0.1b3 - 2.0.2 - 2.0.3a1 - 2.0.3a2 - 2.0.3a3 - 2.0.3a4 - 2.0.3a5 - 2.0.3a6 - 2.0.3a7 - 2.1.0 - 2.2.0 - 2.2.0.dev1 - 2.2.0a1 - 2.2.0a2 - 2.2.0a3 - 2.2.0a4 - 2.2.0a5 - 2.2.0a6 - 2.2.1 - 2.3.0 - 2.3.1 - 2.3.2 - 2.3.3 - 2.3.4 - 2.3.5 - 2.3.6 - 2.3.7 - 2.3.8 - 2.3.9 - 2.4.0 - 2.4.1 - 2.4.2 - 2.4.3 - 2.4.4 - 2.4.5 - 2.4.6 - 2.4.7 - 2.4.8 - 2.4.9 aliases: - CVE-2022-3371 - GHSA-3fhq-72hw-jqwv details: Allocation of Resources Without Limits or Throttling in GitHub repository ikus060/rdiffweb prior to 2.5.0a3. id: PYSEC-2022-299 modified: '2026-06-10T16:51:59.958357Z' published: '2022-09-30T14:15:00Z' references: - type: EVIDENCE url: https://huntr.dev/bounties/4e8f6136-50c7-4fa1-ac98-699bcb7b35ce - type: WEB url: https://huntr.dev/bounties/4e8f6136-50c7-4fa1-ac98-699bcb7b35ce - type: FIX url: https://huntr.dev/bounties/4e8f6136-50c7-4fa1-ac98-699bcb7b35ce - type: FIX url: https://github.com/ikus060/rdiffweb/commit/b62c479ff6979563c7c23e7182942bc4f460a2c7 - type: ADVISORY url: https://github.com/advisories/GHSA-3fhq-72hw-jqwv