Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-7592

25
FAUCET Score

CVE-2024-7592 is a low-severity vulnerability in CPython's 'http.cookies' module, affecting Python installations. It involves a quadratic complexity algorithm when parsing cookie values with backslashes for quoted characters, leading to excessive CPU usage. With a CVSS score of 7.5 (HIGH), this vulnerability is remotely exploitable with low attack complexity, potentially causing a denial of service due to resource exhaustion. There is no evidence of active exploitation, public exploit code, or inclusion in the KEV catalog, though it has received minimal community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.8.20CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.9.0, < 3.9.20CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.10.0, < 3.10.15CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.11.0, < 3.11.10CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*
>= 3.12.0, < 3.12.6CPE matchmatch criteria
cpe:2.3:a:python:python:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
2.30%
Probability of exploitation in next 30 days
EPSS Percentile
81.5%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0230 is in the 67th percentile among its peer group of 51,551 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (34)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 3.9.19-4
microsoftpatch availablevia msrc
Product: 17653-17084Fixed in: 2.16.1-6
microsoftpatch availablevia msrc
Product: 17667-17084Fixed in: 2.16.1-6
microsoftpatch availablevia msrc
Product: 17654-17084Fixed in: 3.12.3-2
microsoftpatch availablevia msrc
Product: 17545-17084Fixed in: 3.12.3-2
microsoftpatch availablevia msrc
Product: cbl2 python3 3.9.19-4 on CBL Mariner 2.0Fixed in: 3.9.19-4
microsoftpatch availablevia msrc
Product: cbl2 python3 3.9.19-13 on CBL Mariner 2.0Fixed in: 3.9.19-4
microsoftpatch availablevia msrc
Product: azl3 tensorflow 2.16.1-6 on Azure Linux 3.0Fixed in: 2.16.1-6
microsoftpatch availablevia msrc
Product: azl3 tensorflow 2.16.1-9 on Azure Linux 3.0Fixed in: 2.16.1-6
microsoftpatch availablevia msrc
Product: azl3 python3 3.12.3-2 on Azure Linux 3.0Fixed in: 3.12.3-2
microsoftpatch availablevia msrc
Product: azl3 python3 3.12.3-5 on Azure Linux 3.0Fixed in: 3.12.3-2
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 3.12.3-2
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 2.16.1-6
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 3.12.3-2
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 2.16.1-6
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 3.9.19-4
microsoftpatch availablevia msrc
Product: 17252-16823Fixed in: 3.9.19-4
microsoftpatch availablevia msrc
Product: 19681-17086Fixed in: 3.9.19-4
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.12-0:3.12.5-2.el9_5.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.11-0:3.11.9-7.el9_5.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python3.9-0:3.9.21-1.el9_5
View patch
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: python
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: python
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: python3
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: gimp:flatpak/python2
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3.11
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python3.12
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python36:3.6/python36
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python39:3.9/python39
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python39-devel:3.9/python39
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux AI (RHEL AI)Fixed in: rhelai1/bootc-nvidia-rhel9
redhatvendor investigatingvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: python3.12

Vendor Advisories (3)

microsoft2024-Oct/CVE-2024-7592

CVE-2024-7592

Oct 8, 2024
redhatCVE-2024-7592Low

cpython: python: Uncontrolled CPU resource consumption when in http.cookies module

Aug 19, 2024
microsoft2024-Aug/CVE-2024-7592Important

Quadratic complexity parsing cookies with backslashes

Aug 13, 2024

References

lists.debian.org / debian-lts-announce/2024/12/msg00000.html
security.netapp.com / advisory/ntap-20241018-0006
Third Party Advisory
github.com / python/cpython/commit/391e5626e3ee5af267b97e37abc7475732e67621
Patch
github.com / python/cpython/commit/44e458357fca05ca0ae2658d62c8c595b048b5ef
Patch
github.com / python/cpython/commit/a77ab24427a18bff817025adb03ca920dc3f1a06
Patch
github.com / python/cpython/commit/b2f11ca7667e4d57c71c1c88b255115f16042d9a
Patch
github.com / python/cpython/commit/d4ac921a4b081f7f996a5d2b101684b67ba0ed7f
Patch
github.com / python/cpython/commit/d662e2db2605515a767f88ad48096b8ac623c774
Patch
github.com / python/cpython/commit/dcc3eaef98cd94d6cb6cb0f44bd1c903d04f33b1
Patch
github.com / python/cpython/issues/123067
ExploitIssue TrackingPatch
github.com / python/cpython/pull/123075
Issue TrackingPatch
mail.python.org / archives/list/[email protected]/thread/HXJAAAALNUNGCQUS2W7WR6GFIZIHFOOK
Mailing List