← Back

CVE-2024-7592

nvd nist
Published: Aug 19, 2024Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module. When parsing cookies that contained backslashes for quoted characters in the cookie value, the parser would use an algorithm with quadratic complexity, resulting in excess CPU resources being used while parsing the value.

Affected (17)

Products: Python: Python
1 product
Python
Configuration A
17 vulnerable
Vulnerable SoftwareAffected Versions
Python
Before 3.8.20
From 3.10.0 to 3.10.15
From 3.11.0 to 3.11.10
From 3.12.0 to 3.12.6
From 3.9.0 to 3.9.20
Version 3.13.0 alpha0
Version 3.13.0 alpha1
Version 3.13.0 alpha2
Version 3.13.0 alpha3
Version 3.13.0 alpha4
Version 3.13.0 alpha5
Version 3.13.0 alpha6
Version 3.13.0 beta1
Version 3.13.0 beta2
Version 3.13.0 beta3
Version 3.13.0 beta4
Version 3.13.0 rc1

Timeline

No history available yet.