PT-2024-7268 · Python+11 · Cpython+11

·

CVE-2024-7592

·

Published

2024-08-19

·

Updated

2026-05-05

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: CPython versions prior to 3.13.0
Description: The issue is related to the 'http.cookies' standard library module in CPython. When parsing cookies that contain backslashes for quoted characters in the cookie value, the parser uses an algorithm with quadratic complexity, resulting in excess CPU resources being used while parsing the value. This could allow a remote attacker to cause a denial of service. The estimated number of potentially affected devices is not specified.
Recommendations: To resolve the issue, apply the available patch immediately to mitigate the risk of system slowdown or crash. As a temporary workaround, consider restricting the use of the 'http.cookies' module until a patch is available. Avoid using the http.cookies module to parse cookies with backslashes for quoted characters in the cookie value until the issue is resolved.

Exploit

Fix

DoS

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025:3631
ALSA-2025:3634
ALT-PU-2024-12989
ALT-PU-2024-12993
ALT-PU-2024-13457
ALT-PU-2024-13459
ALT-PU-2024-14497
AZL-47860
AZL-47865
AZL-48036
BDU:2024-08618
BIT-LIBPYTHON-2024-7592
BIT-PYTHON-2024-7592
BIT-PYTHON-MIN-2024-7592
CVE-2024-7592
DLA-3980-1
DLA-4354-1
INFSA-2025_3631
INFSA-2025_3634
MGASA-2024-0317
OESA-2024-2116
OESA-2024-2117
OESA-2024-2118
OESA-2024-2119
OPENSUSE-SU-2024:14326-1
OPENSUSE-SU-2024:14345-1
OPENSUSE-SU-2024:14346-1
OPENSUSE-SU-2024:14352-1
OPENSUSE-SU-2024:14370-1
OPENSUSE-SU-2024:14434-1
OPENSUSE-SU-2024_3303-1
OPENSUSE-SU-2024_3357-1
OPENSUSE-SU-2024_3411-1
OPENSUSE-SU-2024_3418-1
OPENSUSE-SU-2024_3427-1
OPENSUSE-SU-2024_3470-1
OPENSUSE-SU-2025:15713-1
PSF-2024-9
RHSA-2024:10983
RHSA-2024_10983
RHSA-2025:3631
RHSA-2025:3634
RHSA-2025_3631
RHSA-2025_3634
SUSE-EL-9-CLIENT-TOOLS-2024-4029
SUSE-SU-2024:3293-1
SUSE-SU-2024:3302-1
SUSE-SU-2024:3303-1
SUSE-SU-2024:3357-1
SUSE-SU-2024:3384-1
SUSE-SU-2024:3411-1
SUSE-SU-2024:3418-1
SUSE-SU-2024:3427-1
SUSE-SU-2024:3470-1
SUSE-SU-2024:4020-1
SUSE-SU-2024:4021-1
SUSE-SU-2024:4029-1
SUSE-SU-2025:20065-1
SUSE-SU-2025:20154-1
SUSE-SU-2025:20374-1
SUSE-SU-2026:0774-1
SUSE-SU-2026:0802-1
USN-7015-1
USN-7015-2
USN-7015-6

Affected Products

Alt Linux
Almalinux
Astra Linux
Cpython
Debian
Ibm Aix
Linuxmint
Red Hat
Red Os
Rocky Linux
Suse
Ubuntu