There is a LOW severity vulnerability affecting CPython, specifically the
'http.cookies' standard library module.


When parsing cookies that contained backslashes for quoted characters in
the cookie value, the parser would use an algorithm with quadratic
complexity, resulting in excess CPU resources being used while parsing the
value.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-3980-1 python3.9 security update
Debian DLA Debian DLA DLA-4354-1 pypy3 security update
Ubuntu USN Ubuntu USN USN-7015-1 Python vulnerabilities
Ubuntu USN Ubuntu USN USN-7015-2 Python vulnerabilities
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Tue, 04 Nov 2025 08:30:00 +0900

Type Values Removed Values Added
References

Wed, 16 Jul 2025 22:45:00 +0900

Type Values Removed Values Added
Metrics epss

{'score': 0.00325}

epss

{'score': 0.0036}


Tue, 08 Apr 2025 11:45:00 +0900

Type Values Removed Values Added
First Time appeared Redhat
Redhat enterprise Linux
CPEs cpe:/a:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux

Sat, 01 Feb 2025 05:15:00 +0900


Fri, 22 Nov 2024 21:00:00 +0900

Type Values Removed Values Added
References

Thu, 05 Sep 2024 05:30:00 +0900


Wed, 04 Sep 2024 03:30:00 +0900

Type Values Removed Values Added
First Time appeared Python cpython
CPEs cpe:2.3:a:python:cpython:*:*:*:*:*:*:*:*
Vendors & Products Python cpython
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 04 Sep 2024 00:15:00 +0900


Wed, 21 Aug 2024 06:30:00 +0900

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Low


Wed, 21 Aug 2024 01:30:00 +0900

Type Values Removed Values Added
First Time appeared Python
Python python
Weaknesses CWE-1333
CPEs cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
cpe:2.3:a:python:python:3.13.0:alpha0:*:*:*:*:*:*
cpe:2.3:a:python:python:3.13.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:python:python:3.13.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:python:python:3.13.0:alpha3:*:*:*:*:*:*
cpe:2.3:a:python:python:3.13.0:alpha4:*:*:*:*:*:*
cpe:2.3:a:python:python:3.13.0:alpha5:*:*:*:*:*:*
cpe:2.3:a:python:python:3.13.0:alpha6:*:*:*:*:*:*
cpe:2.3:a:python:python:3.13.0:beta1:*:*:*:*:*:*
cpe:2.3:a:python:python:3.13.0:beta2:*:*:*:*:*:*
cpe:2.3:a:python:python:3.13.0:beta3:*:*:*:*:*:*
cpe:2.3:a:python:python:3.13.0:beta4:*:*:*:*:*:*
cpe:2.3:a:python:python:3.13.0:rc1:*:*:*:*:*:*
Vendors & Products Python
Python python
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}


Tue, 20 Aug 2024 04:15:00 +0900

Type Values Removed Values Added
Description There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module. When parsing cookies that contained backslashes for quoted characters in the cookie value, the parser would use an algorithm with quadratic complexity, resulting in excess CPU resources being used while parsing the value.
Title Quadratic complexity parsing cookies with backslashes
Weaknesses CWE-400
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: PSF

Published:

Updated: 2025-11-03T22:32:52.863Z

Reserved: 2024-08-07T15:53:07.135Z

Link: CVE-2024-7592

cve-icon Vulnrichment

Updated: 2024-10-18T13:07:47.143Z

cve-icon NVD

Status : Modified

Published: 2024-08-19T19:15:08.180

Modified: 2025-11-03T23:17:31.847

Link: CVE-2024-7592

cve-icon Redhat

Severity : Low

Publid Date: 2024-08-19T00:00:00Z

Links: CVE-2024-7592 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses