spyne@2.13.16 vulnerabilities

A transport and architecture agnostic rpc library that focuses on exposing public services with a well-defined API.

Direct Vulnerabilities

Known vulnerabilities in the spyne package. This does not include vulnerabilities belonging to this package’s dependencies.

Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for free
Vulnerability Vulnerable Version
  • M
Regular Expression Denial of Service (ReDoS)

spyne is an A transport and architecture agnostic rpc library that focuses on exposing public services with a well-defined API.

Affected versions of this package are vulnerable to Regular Expression Denial of Service (ReDoS) via an inefficient expression.

How to fix Regular Expression Denial of Service (ReDoS)?

Upgrade spyne to version 2.14.0 or higher.

[,2.14.0)