holidays is vulnerable to Regular Expression Denial of Service (ReDoS)
50
Medium Risk
The affected versions use a regular expression with inefficient, potentially polynomial worst-case computational complexity, leading to excessive CPU consumption in scripts/generate_release_notes.py.
You are affected if you are using a version that falls within the vulnerable range.
holidays is vulnerable to Regular Expression Denial of Service (ReDoS) in versions 0.1 - 0.44.
Upgrade the holidays library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant