IsItPatchedInstant security status for any software version
← All products

CVE-2024-7592

HIGH severity · CVSS 7.5 · Uncontrolled resource consumption
7.5CVSS HIGH

Summary

There is a LOW severity vulnerability affecting CPython, specifically the 'http.cookies' standard library module. When parsing cookies that contained backslashes for quoted characters in the cookie value, the parser would use an algorithm with quadratic complexity, resulting in excess CPU resources being used while parsing the value.

Impact & exploitability

Attack vectorNetwork
Attack complexityLow
Privileges requiredNone
User interactionNone
Confidentiality impactNone
Integrity impactNone
Availability impactHigh
Exploit probability (EPSS)1%

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products we track (1)

Recommendation

Apply the vendor fix promptly. Open any affected product above for its exact safe version.

Official patch: https://github.com/python/cpython/commit/391e5626e3ee5af267b97e37abc7475732e67621 ↗

Last checked: Wed, 10 Jun 2026 22:18:30 UTC