CVE-2020-8492

Published
View on NVD ↗
CVSS v3
6.5
MEDIUM
CVSS v2
7.1
HIGH
Affected
1
PROJECT

Description

Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.

The Python programming language
GitHubGitHub
73.4K