CVE-2024-46242EPSS p50.9%
CVE-2024-46242CVE-2024-46242
Description
An issue in the validate_email function in CTFd/utils/validators/__init__.py of CTFd 3.7.3 allows attackers to cause a Regular expression Denial of Service (ReDoS) via supplying a crafted string as e-mail address during registration.
Scoring
| CVSS | 7.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
| EPSS | 0.72% probability of exploitation · percentile 50.9% · 2026-08-18T12:04:07Z |
| Last modified | 2026-07-05 |