holidays is vulnerable to Regular Expression Denial of Service (ReDoS)
50
Medium Risk
The affected versions use a regular expression with inefficient, potentially polynomial worst-case computational complexity, leading to excessive CPU consumption in scripts/generate_release_notes.py.
You are affected if you are using a version that falls within the vulnerable range.
holidays is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 0.1 - 0.44.
Upgrade the holidays library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant