CVE-2018-14647

Updated: 2025-08-20 00:36:29.222286

Description:

Python's elementtree C accelerator failed to initialise Expat's hash salt during initialization. This could make it easy to conduct denial of service attacks against Expat by constructing an XML document that would cause pathological hash collisions in Expat's internal data structures, consuming large amounts CPU and RAM. The vulnerability exists in Python versions 3.7.0, 3.6.0 through 3.6.6, 3.5.0 through 3.5.6, 3.4.0 through 3.4.9, 2.7.0 through 2.7.15.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x MEDIUM 5.0
CVSS Version 3.x HIGH 7.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

Alpine Linux 3.22 python 3.7 7.5 HIGH Not Vulnerable 2026-02-16 14:40:29
Alpine Linux 3.22 python 3.6 7.5 HIGH Already Fixed 2026-01-27 16:43:20
Debian 10 python 3.6 7.5 HIGH Already Fixed 2025-09-05 09:16:38
Debian 10 python 2.7 7.5 HIGH Not Vulnerable 2025-09-05 09:16:37
Debian 11 python 2.7 7.5 HIGH Not Vulnerable 2025-09-05 09:16:37
Debian 11 python 3.6 7.5 HIGH Already Fixed 2025-09-05 09:16:38
Debian 12 python 3.7 7.5 HIGH Not Vulnerable 2025-11-12 16:12:42 Not vulnerable: the deployed Python versions are 3.7.17 and 3.8.20, whereas CVE‑2018‑14647 only ...
Debian 12 python 3.6 7.5 HIGH Already Fixed 2025-09-05 09:16:37 Not vulnerable: the deployed Python versions are 3.7.17 and 3.8.20, whereas CVE‑2018‑14647 only ...
Debian 12 python 2.7 7.5 HIGH Not Vulnerable 2025-09-05 09:16:36 Not vulnerable: the deployed Python versions are 3.7.17 and 3.8.20, whereas CVE‑2018‑14647 only ...
Debian 13 python 3.6 7.5 HIGH Already Fixed 2025-09-24 22:30:04
Total: 30