Description


A flaw was found in python. An improperly handled HTTP response in the HTTP client code of python may allow a remote attacker, who controls the HTTP server, to make the client script enter an infinite loop, consuming CPU time. The highest threat from this vulnerability is to system availability.

References


https://bugs.python.org/issue44022

ExploitIssue TrackingVendor Advisory

https://bugzilla.redhat.com/show_bug.cgi?id=1995162

Issue TrackingPatchThird Party Advisory









https://bugs.python.org/issue44022

ExploitIssue TrackingVendor Advisory

https://bugzilla.redhat.com/show_bug.cgi?id=1995162

Issue TrackingPatchThird Party Advisory










Weaknesses



CWE-835


CWE-400CWE-835

CVSS impact metrics


CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.5 · High

Information


Source identifier

[email protected]

Vulnerability status

Modified

Published

2022-03-04T18:15:08.730Z

3 years ago

Last modified

2025-12-17T21:15:56.970Z

2 weeks ago