CVE-2020-8492

⚪ Do wiadomości

Atak ReDoS w Pythonie umożliwia serwerowi HTTP przeciążenie klienta.

CVSS
6.5
EPSS
6.6%
Exploit
poc
Vendor
canonical
Opis źródłowy (NVD)

Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.

dos exploit Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS6.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)6.6%
Opublikowano (NVD)2020-01-30 19:15:12 UTC
Ostatnia modyfikacja (NVD)2026-10-07 19:17:18 UTC
Referencje