{"id":"CVE-2024-21503","aliases":["GHSA-fj7x-q9j7-g6q6","PYSEC-2024-48"],"url":"https://o3.security/vulnerability/CVE-2024-21503","summary":"Black vulnerable to Regular Expression Denial of Service (ReDoS)","details":"Versions of the package black before 24.3.0 are vulnerable to Regular Expression Denial of Service (ReDoS) via the lines_with_leading_tabs_expanded function in the strings.py file. An attacker could exploit this vulnerability by crafting a malicious input that causes a denial of service.\r\rExploiting this vulnerability is possible when running Black on untrusted input, or if you habitually put thousands of leading tab characters in your docstrings.","published":"2024-03-19T05:00:01.474Z","modified":"2026-08-12T03:51:12.684106520Z","cvss":{"score":5.3,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:P"},"epss":{"score":0.00979,"percentile":0.60533,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"black","fixedVersion":"24.3.0"}],"fix":{"url":"https://github.com/psf/black/commit/f00093672628d212b8965a8993cee8bedf5fe9b8","label":"psf/black@f000936"},"references":[{"type":"WEB","url":"https://github.com/psf/black/releases/tag/24.3.0"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-PYTHON-BLACK-6256273"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/21xxx/CVE-2024-21503.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-21503"},{"type":"FIX","url":"https://github.com/psf/black/commit/f00093672628d212b8965a8993cee8bedf5fe9b8"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:12.684106520Z"}}