CVE-2024-5642 is a low-severity vulnerability in CPython 3.9 and earlier, where configuring an empty list for SSLContext.set_npn_protocols() can lead to a buffer over-read when NPN is used, affecting the underlying OpenSSL API. The CVSS score is 6.5 (Medium), indicating potential for low impact on confidentiality and availability with low attack complexity, though NPN is not widely used. There is no evidence of active exploitation, public exploit code, or significant community discussion, suggesting a low immediate threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Python Software Foundation | CPython | >= 0, < 3.10.0b1CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Third-Party Package Updates in Splunk AppDynamics On-Premises Enterprise Console - August 2025
Aug 6, 2025python: Invalid value for OpenSSL API may cause Buffer over-read when NPN is used
Jun 27, 2024Buffer overread when using an empty list with SSLContext.set_npn_protocols()
Jun 11, 2024