Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-5642

21
FAUCET Score

CVE-2024-5642 is a low-severity vulnerability in CPython 3.9 and earlier, where configuring an empty list for SSLContext.set_npn_protocols() can lead to a buffer over-read when NPN is used, affecting the underlying OpenSSL API. The CVSS score is 6.5 (Medium), indicating potential for low impact on confidentiality and availability with low attack complexity, though NPN is not widely used. There is no evidence of active exploitation, public exploit code, or significant community discussion, suggesting a low immediate threat.

Impacted Technologies

VendorProductVersion(s)CPE
Python Software FoundationCPython
>= 0, < 3.10.0b1CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

6.5MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
LOW
Exploitability Score
3.9
Impact Score
2.5
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.74%
Probability of exploitation in next 30 days
EPSS Percentile
51.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0074 is in the 32nd percentile among its peer group of 23,725 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (14)

nodejspatch availablevia llm_extracted
Fixed in: 25.4.0
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python39-devel:3.9-8100020251126112422.d47b87a4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.9-0:3.9.25-2.el9_7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ceph Storage 8Fixed in: rhceph/rhceph-8-rhel9:sha256:09aaeba975aa74bdf95d63e5619c0cabb1cd9e1410aa34e7f8ecf24a5e291d1a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Discovery 2Fixed in: discovery/discovery-server-rhel9:sha256:75723049a444b5136e2d40920e2852f0840fecf60832a8bbb06e488fc9bba543
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Discovery 2Fixed in: discovery/discovery-ui-rhel9:sha256:899bd7f941512d54af8ab369ca03028a7d27d05887ccce24bc12c7ccd3e4dbee
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Update Infrastructure 5Fixed in: rhui5/cds-rhel9:sha256:87d268fd03fa0063620a043b43bce078144e06849ca6b83fd0e375c13ecb15be
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python39:3.9-8100020251126112422.d47b87a4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Update Infrastructure 5Fixed in: rhui5/installer-rhel9:sha256:e1d64fbd0e4b90259d9fbb94736ed74c7c384d13067c6bbbb107c664683cb1a9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Update Infrastructure 5Fixed in: rhui5/rhua-rhel9:sha256:4642951a6a57511f8b481a6481fcd417fc7f3de86511cdab28b9b89639c2bdb2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Update Infrastructure 5Fixed in: rhui5/haproxy-rhel9:sha256:c0cb48d44556c064626eab0d70e5f427ac132bbd921342dcb862267413bf8d16
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: inkscape:flatpak/python2
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python27:2.7/python2
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: gimp:flatpak/python2

Vendor Advisories (3)

nodejsllm-nodejs-9e1762a1939f642dCRITICAL

Third-Party Package Updates in Splunk AppDynamics On-Premises Enterprise Console - August 2025

Aug 6, 2025
redhatCVE-2024-5642Low

python: Invalid value for OpenSSL API may cause Buffer over-read when NPN is used

Jun 27, 2024
microsoft2024-Jun/CVE-2024-5642Moderate

Buffer overread when using an empty list with SSLContext.set_npn_protocols()

Jun 11, 2024

References

github.com / python/cpython/commit/39258d3595300bc7b952854c915f63ae2d4b9c3e
github.com / python/cpython/commit/a2cdbb6e8188ba9ba8b356b28d91bff60e86fe31
github.com / python/cpython/issues/121227
github.com / python/cpython/pull/23014
jbp.io / 2024/06/27/cve-2024-5535-openssl-memory-safety.html
mail.python.org / archives/list/[email protected]/thread/PLP2JI3PJY33YG6P5BZYSSNU66HASXBQ
security.netapp.com / advisory/ntap-20240726-0005
openwall.com / lists/oss-security/2024/06/28/4