The probability is the direct output of the EPSS model, and conveys an overall sense of the threat of exploitation in the wild. The percentile measures the EPSS probability relative to all known EPSS scores. Note: This data is updated daily, relying on the latest available EPSS model version. Check out the EPSS documentation for more details.
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applicationsUpgrade python/cpython to version 3.15.0rc2 or higher.
Affected versions of this package are vulnerable to Behavioral Change in New Version or Environment in Lib/stringprep.py and the encodings.idna codec. An attacker can trigger domain-name mismatches by supplying IDNA 2003 hostnames that contain characters whose Unicode properties were added or changed after Unicode 3.2.0. This breaks RFC 3454 handling in in_table_b2()-related processing and can cause hostnames to be encoded or decoded inconsistently, leading to failed name resolution or interoperability problems for affected users.