CVE-2020-8492

Updated: 2026-01-19 04:12:56.957523

Description:

Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.


Links NIST CIRCL RHEL Ubuntu

Severity

Severity Score
CVSS Version 2.x HIGH 7.1
CVSS Version 3.x MEDIUM 6.5

Status

OS name Project name Version Score Severity Status Errata Last updated

Statement

EL 9 python 2.7 6.5 MEDIUM Released CLSA-2025:1754039871 2025-08-02 00:15:53
Ubuntu 16.04 python 2.7 6.5 MEDIUM Released CLSA-2025:1760370210 2025-10-13 17:07:36
Ubuntu 16.04 python 3.6 6.5 MEDIUM Already Fixed 2025-08-15 00:39:56
Ubuntu 18.04 python 2.7 6.5 MEDIUM Released CLSA-2025:1760370140 2025-10-13 17:07:32
Ubuntu 18.04 python 3.6 6.5 MEDIUM Already Fixed 2025-08-15 00:39:55
Ubuntu 20.04 python 2.7 6.5 MEDIUM Released CLSA-2025:1760369449 2025-10-13 17:07:30
Ubuntu 20.04 python 3.6 6.5 MEDIUM Already Fixed 2025-08-15 00:39:54
Ubuntu 22.04 python 2.7 6.5 MEDIUM Released CLSA-2025:1760369318 2025-10-13 17:07:29
Ubuntu 22.04 python 3.6 6.5 MEDIUM Already Fixed 2025-08-15 00:39:57
Ubuntu 24.04 python 2.7 6.5 MEDIUM Released CLSA-2025:1760369107 2025-10-13 17:07:28
Total: 31