The Validators Project maintains a focused validation library that, despite limited scope, sees broad reuse across input-sanitization and data-verification workflows in web applications and services. Its durable vulnerability signal centers on the validators product and recurs through weakness classes including inefficient regular expression complexity and infinite-loop conditions that reflect the parsing demands of a general-purpose validation toolkit. Current vulnerability counts, severity, and exploitation details are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Validators Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-19588HIGH The validators package 0.12.2 through 0.12.5 for Python enters an infinite loop when validators.domain is called with a crafted domain string. This is fixed in 0.12.6. | Dec 5, 2019 | 7.5 | 24 | NO | NO |
CVE-2023-45813HIGH Torbot is an open source tor network intelligence tool. In affected versions the `torbot.modules.validators.validate_link function` uses the python-validators URL validation regex. | Oct 18, 2023 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Validators Project.
Media articles that mention a CVE ID that affects a product developed by Validators Project — matched by CVE ID, not by vendor name.