[CVE-2017-16116](https://nvd.nist.gov/vuln/detail/CVE-2017-16116) **high severity** Vulnerable versions: <= 3.3.3 >The string module is vulnerable to regular expression denial of service when specifically crafted untrusted user input is passed into the underscore or unescapeHTML methods.
This issue appears to be discussing a feature request or bug report related to the repository. Based on the content, it seems to be still under discussion. The issue was opened by joarwilk and has received 7 comments.