CVE-2025-0938 DetailsANALYZED This CVE record has been analyzed and enriched by NVDAPI.com as an independent party.
Description The Python standard library functions `urllib.parse.urlsplit` and `urlparse` accepted domain names that included square brackets which isn't valid according to RFC 3986. Square brackets are only meant to be used as delimiters for specifying IPv6 and IPvFuture hosts in URLs. This could result in differential parsing across the Python URL parser and other specification-compliant URL parsers.
A vulnerability exists in the Python standard library's urllib module, specifically in the urlsplit and urlparse functions. These functions improperly accept domain names that include square brackets, which is not compliant with RFC 3986. Square brackets should only be used to delimit IPv6 and IPvFuture addresses in URLs. This flaw can lead to inconsistent URL parsing between Python's parser and other parsers that adhere to the specification.
Users can update to Python versions 3.9.23, 3.10.13, 3.11.13, 3.12.0, or 3.13.0, where this issue has been fixed.
Show AI summary Metrics CVSS Version 4.0 CVSS Version 3.x CVSS Version 2.0 SSVC
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 31, 2025 Exploitation: NoneAutomatable: NoTechnical Impact: Partial
CISA-ADP
Assessed Jan 31, 2025 Exploitation: NoneAutomatable: NoTechnical Impact: Partial
References to Advisories, Solutions, and Tools By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration Affected Products Product Versions Python >= 3.9, < 3.9.23
>= 3.10, < 3.10.12
>= 3.11, < 3.11.6
>= 3.12, < 3.12.2
>= 3.13, < 3.13.1
CPE cpe:2.3:a:python:python:*:*:*:*:*:*:*:* Remediation Upgrade: 3.9.23moderate effort Upgrade: 3.10.12moderate effort Upgrade: 3.11.6moderate effort Upgrade: 3.12.2moderate effort Upgrade: 3.13.1moderate effort NetApp All versions
CPE cpe:2.3:a:netapp:brocade_network_advisor:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:cloud_backup:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:cluster_data_ontap:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:data_ontap:*:*:*:*:*:7-mode:*:* cpe:2.3:a:netapp:element_software:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:max_data:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:netapp_plug-in:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:ontap:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:ontap_9:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:solidfire:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:storagegrid:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:storagegrid_webscale:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:symantec_netbackup:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:system_manager:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:trident:*:*:*:*:*:*:*:* cpe:2.3:a:netapp:virtual_file_mangemer:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:500f:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:8300:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:8700:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:a220:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:a320:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:a800:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:aff_a200:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:aff_a900:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:c250:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:c400:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fabric-attached_storage_8700:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fas2600:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fas26x0:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fas27x0:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fas8700:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:fas9000:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:h300s:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:h410s:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:h500e:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:h610s:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:h615c:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:h700e:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:h700s:*:*:*:*:*:*:*:* cpe:2.3:h:netapp:storagegrid:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:500f_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:8300_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:8700_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:a220_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:a320_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:a800_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:aff_a200_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:aff_a900_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:brocade_fabric_os:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:c250_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:c400_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:clustered_data_ontap:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:data_ontap:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:data_ontap:*:*:*:*:*:7-mode:*:* cpe:2.3:o:netapp:element:*:*:*:*:*:vcenter_server:*:* cpe:2.3:o:netapp:element_os:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:fas2600_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:fas26x0_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:fas27x0_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:fas8700_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:fas9000_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:h300s_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:h410s_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:h500e_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:h610s_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:h615c_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:h700e_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:h700s_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:netapp:storagegrid_firmware:*:*:*:*:*:*:*:* Remediation No remediation found in references.
Change History 10 change records found show changes
Date Action Recorded By Jul 31, 2026 CVE Modified [email protected] Jul 30, 2026 CVE Modified [email protected] Jun 17, 2026 CVE Modified CISA-ADP Jun 17, 2026 CVE Modified [email protected] Nov 3, 2025 CVE Modified CVE Mar 14, 2025 CVE Modified CVE Feb 28, 2025 CVE Modified [email protected] Feb 4, 2025 CVE Modified [email protected] Jan 31, 2025 CVE Modified [email protected] Jan 31, 2025 New CVE Received [email protected]