T
here is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module. When parsing cookies that contained backslashes for quoted characters in the cookie value, the parser would use an algorithm with quadratic complexity, resulting in excess CPU resources being used while parsing the value.
References
Configurations
Configuration 1 (hide)
|
History
03 Nov 2025, 23:17
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
05 Feb 2025, 21:13
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/python/cpython/commit/391e5626e3ee5af267b97e37abc7475732e67621 - Patch | |
| References | () https://github.com/python/cpython/commit/44e458357fca05ca0ae2658d62c8c595b048b5ef - Patch | |
| References | () https://github.com/python/cpython/commit/a77ab24427a18bff817025adb03ca920dc3f1a06 - Patch | |
| References | () https://github.com/python/cpython/commit/b2f11ca7667e4d57c71c1c88b255115f16042d9a - Patch | |
| References | () https://github.com/python/cpython/commit/d4ac921a4b081f7f996a5d2b101684b67ba0ed7f - Patch | |
| References | () https://github.com/python/cpython/commit/d662e2db2605515a767f88ad48096b8ac623c774 - Patch | |
| References | () https://github.com/python/cpython/commit/dcc3eaef98cd94d6cb6cb0f44bd1c903d04f33b1 - Patch | |
| References | () https://security.netapp.com/advisory/ntap-20241018-0006/ - Third Party Advisory |
31 Jan 2025, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
21 Nov 2024, 09:51
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
04 Sep 2024, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
03 Sep 2024, 15:15
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
20 Aug 2024, 16:02
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:python:python:3.13.0:alpha4:*:*:*:*:*:* cpe:2.3:a:python:python:3.13.0:rc1:*:*:*:*:*:* cpe:2.3:a:python:python:3.13.0:beta3:*:*:*:*:*:* cpe:2.3:a:python:python:3.13.0:alpha0:*:*:*:*:*:* cpe:2.3:a:python:python:3.13.0:alpha6:*:*:*:*:*:* cpe:2.3:a:python:python:*:*:*:*:*:*:*:* cpe:2.3:a:python:python:3.13.0:beta1:*:*:*:*:*:* cpe:2.3:a:python:python:3.13.0:beta2:*:*:*:*:*:* cpe:2.3:a:python:python:3.13.0:alpha2:*:*:*:*:*:* cpe:2.3:a:python:python:3.13.0:beta4:*:*:*:*:*:* cpe:2.3:a:python:python:3.13.0:alpha3:*:*:*:*:*:* cpe:2.3:a:python:python:3.13.0:alpha1:*:*:*:*:*:* cpe:2.3:a:python:python:3.13.0:alpha5:*:*:*:*:*:* |
|
| CWE | CWE-1333 | |
| References | () https://github.com/python/cpython/issues/123067 - Exploit, Issue Tracking, Patch | |
| References | () https://github.com/python/cpython/pull/123075 - Issue Tracking, Patch | |
| References | () https://mail.python.org/archives/list/[email protected]/thread/HXJAAAALNUNGCQUS2W7WR6GFIZIHFOOK/ - Mailing List | |
| First Time |
Python python
Python |
|
| Summary |
|
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
19 Aug 2024, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2024-08-19 19:15
Updated : 2025-11-03 23:17
NVD link : CVE-2024-7592
Mitre link : CVE-2024-7592
CVE.ORG link : CVE-2024-7592
JSON object : View