Pytest is a widely adopted Python testing framework that, despite a narrow product footprint, sits deep in the development workflow across numerous projects and environments. The observed vulnerability profile centers on the core pytest package and reflects weaknesses related to regular expression handling complexity, typical of parsing and pattern-matching operations in test automation tools. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pytest over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-42969HIGH The py library through 1.11.0 for Python allows remote attackers to conduct a ReDoS (Regular expression Denial of Service) attack via a Subversion repository with crafted info data | Oct 16, 2022 | 7.5 | 26 | NO | NO |
CVE-2020-29651HIGH A denial of service via regular expression in the py.path.svnwc component of py (aka python-py) through 1.9.0 could be used by attackers to cause a compute-time denial of service a | Dec 9, 2020 | 7.5 | 26 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pytest.
Media articles that mention a CVE ID that affects a product developed by Pytest — matched by CVE ID, not by vendor name.