'http.cookies' standard library module.
When parsing cookies that contained backslashes for quoted characters in
the cookie value, the parser would use an algorithm with quadratic
complexity, resulting in excess CPU resources being used while parsing the
value.
Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3980-1 | python3.9 security update |
Debian DLA |
DLA-4354-1 | pypy3 security update |
Ubuntu USN |
USN-7015-1 | Python vulnerabilities |
Ubuntu USN |
USN-7015-2 | Python vulnerabilities |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Mon, 03 Nov 2025 23:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 08 Apr 2025 02:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Redhat
Redhat enterprise Linux |
|
| CPEs | cpe:/a:redhat:enterprise_linux:9 | |
| Vendors & Products |
Redhat
Redhat enterprise Linux |
Fri, 31 Jan 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 22 Nov 2024 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Wed, 04 Sep 2024 20:30:00 +0000
Tue, 03 Sep 2024 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Python cpython
|
|
| CPEs | cpe:2.3:a:python:cpython:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Python cpython
|
|
| Metrics |
ssvc
|
Tue, 03 Sep 2024 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 20 Aug 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Tue, 20 Aug 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Python
Python python |
|
| Weaknesses | CWE-1333 | |
| CPEs | cpe:2.3:a:python:python:*:*:*:*:*:*:*:* cpe:2.3:a:python:python:3.13.0:alpha0:*:*:*:*:*:* cpe:2.3:a:python:python:3.13.0:alpha1:*:*:*:*:*:* cpe:2.3:a:python:python:3.13.0:alpha2:*:*:*:*:*:* cpe:2.3:a:python:python:3.13.0:alpha3:*:*:*:*:*:* cpe:2.3:a:python:python:3.13.0:alpha4:*:*:*:*:*:* cpe:2.3:a:python:python:3.13.0:alpha5:*:*:*:*:*:* cpe:2.3:a:python:python:3.13.0:alpha6:*:*:*:*:*:* cpe:2.3:a:python:python:3.13.0:beta1:*:*:*:*:*:* cpe:2.3:a:python:python:3.13.0:beta2:*:*:*:*:*:* cpe:2.3:a:python:python:3.13.0:beta3:*:*:*:*:*:* cpe:2.3:a:python:python:3.13.0:beta4:*:*:*:*:*:* cpe:2.3:a:python:python:3.13.0:rc1:*:*:*:*:*:* |
|
| Vendors & Products |
Python
Python python |
|
| Metrics |
cvssV3_1
|
Mon, 19 Aug 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module. When parsing cookies that contained backslashes for quoted characters in the cookie value, the parser would use an algorithm with quadratic complexity, resulting in excess CPU resources being used while parsing the value. | |
| Title | Quadratic complexity parsing cookies with backslashes | |
| Weaknesses | CWE-400 | |
| References |
|
Status: PUBLISHED
Assigner: PSF
Published:
Updated: 2025-11-03T22:32:52.863Z
Reserved: 2024-08-07T15:53:07.135Z
Link: CVE-2024-7592
Updated: 2024-10-18T13:07:47.143Z
Status : Modified
Published: 2024-08-19T19:15:08.180
Modified: 2025-11-03T23:17:31.847
Link: CVE-2024-7592
OpenCVE Enrichment
No data.
Debian DLA
Ubuntu USN