CVE-2024-6232
published 2024-09-03CVE-2024-6232: There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
2.20%
80.5th percentile
There is a MEDIUM severity vulnerability affecting CPython.
Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.
Affected
27 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | pypy3 | < pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) | pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) |
| debian | python2.7 | < pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) | pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) |
| debian | python3.11 | < pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) | pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) |
| debian | python3.13 | < pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) | pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) |
| debian | python3.9 | < pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) | pypy3 7.3.5+dfsg-2+deb11u5 (bullseye) |
| msrc | azl3_python3_3.12.3-4_on_azure_linux_3.0 | — | — |
| msrc | azl3_python3_3.12.3-5_on_azure_linux_3.0 | — | — |
| msrc | azl3_tensorflow_2.16.1-7_on_azure_linux_3.0 | — | — |
| msrc | azl3_tensorflow_2.16.1-9_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_python3_3.9.19-13_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_python3_3.9.19-5_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| python | python | < 3.8.20 | 3.8.20 |
| python | python | — | — |
| python | python | >= 3.10.0 < 3.10.15 | 3.10.15 |
| python | python | >= 3.11.0 < 3.11.10 | 3.11.10 |
| python | python | >= 3.12.0 < 3.12.6 | 3.12.6 |
| python | python | >= 3.9.0 < 3.9.20 | 3.9.20 |
| python_software_foundation | cpython | < 3.8.20 | 3.8.20 |
| python_software_foundation | cpython | >= 3.10.0 < 3.10.15 | 3.10.15 |
| python_software_foundation | cpython | >= 3.11.0 < 3.11.10 | 3.11.10 |
| python_software_foundation | cpython | >= 3.12.0 < 3.12.6 | 3.12.6 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
python2.7 regression
osv·2025-09-29·CVSS 5.3
CVE-2023-27043 [MEDIUM] python2.7 regression
python2.7 regression
USN-7015-4 fixed vulnerabilities in Python. It was discovered that the fix
for CVE-2023-27043 for python2.7 was incorrectly applied on Ubuntu 16.04
LTS and Ubuntu 18.04 LTS. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the Python email module incorrectly parsed email
addresses that contain special characters. A remote attacker could
possibly use this issue to bypass certain protection mechanisms.
(CVE-2023-27043)
It was discovered that Python allowed excessive backtracking while parsing
certain tarfile headers. A remote attacker could possibly use this issue
to cause Python to consume resources, leading to a denial of service.
(CVE-2024-6232)
It was discovered that the Python email module inc
OSV
python vulnerabilities
osv·2025-05-06·CVSS 6.3
CVE-2024-11168 [MEDIUM] python vulnerabilities
python vulnerabilities
It was discovered that Python incorrectly handled parsing bracketed hosts.
A remote attacker could possibly use this issue to perform a Server-Side
Request Forgery (SSRF) attack. This issue only affected python 2.7 and
python3.4 on Ubuntu 14.04 LTS; python2.7 on Ubuntu 16.04 LTS;
python2.7, python3.6, python3.7, and python3.8 on Ubuntu 18.04 LTS;
python2.7 and python3.9 on Ubuntu 20.04 LTS; and python2.7 and
python3.11 on Ubuntu 22.04 LTS. (CVE-2024-11168)
It was discovered that Python allowed excessive backtracking while
parsing certain tarfile headers. A remote attacker could possibly use
this issue to cause Python to consume excessive resources, leading to
a denial of service. This issue only affected python3.4 on
Ubuntu 14.04 LTS; python3.6, python3.7, and pyth
OSV
python2.7 regresssions
osv·2024-11-22·CVSS 5.3
CVE-2023-27043 [MEDIUM] python2.7 regresssions
python2.7 regresssions
USN-7015-5 fixed vulnerabilities in python2.7. The update introduced
several minor regressions. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the Python email module incorrectly parsed email
addresses that contain special characters. A remote attacker could
possibly use this issue to bypass certain protection mechanisms.
(CVE-2023-27043)
It was discovered that Python allowed excessive backtracking while parsing
certain tarfile headers. A remote attacker could possibly use this issue
to cause Python to consume resources, leading to a denial of service.
(CVE-2024-6232)
It was discovered that the Python email module incorrectly quoted newlines
for email headers. A remote attacker could possibly
OSV
python2.7 vulnerabilities
osv·2024-11-19·CVSS 5.3
CVE-2024-6232 [MEDIUM] python2.7 vulnerabilities
python2.7 vulnerabilities
USN-7015-1 fixed several vulnerabilities in Python. This update provides
the corresponding update for CVE-2024-6232 and CVE-2024-6923 for python2.7
in Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS
and Ubuntu 22.04 LTS.
Original advisory details:
It was discovered that the Python email module incorrectly parsed email
addresses that contain special characters. A remote attacker could
possibly use this issue to bypass certain protection mechanisms.
(CVE-2023-27043)
It was discovered that Python allowed excessive backtracking while parsing
certain tarfile headers. A remote attacker could possibly use this issue
to cause Python to consume resources, leading to a denial of service.
(CVE-2024-6232)
It was discovered that the Python email mod
OSV
python2.7, python3.5 vulnerability
osv·2024-10-14·CVSS 5.3
CVE-2023-27043 [MEDIUM] python2.7, python3.5 vulnerability
python2.7, python3.5 vulnerability
USN-7015-1 fixed several vulnerabilities in Python. This update provides the
corresponding update for CVE-2023-27043 for python2.7 and python3.5 in
Ubuntu 14.04 LTS.
Original advisory details:
It was discovered that the Python email module incorrectly parsed email
addresses that contain special characters. A remote attacker could
possibly use this issue to bypass certain protection mechanisms.
(CVE-2023-27043)
It was discovered that Python allowed excessive backtracking while parsing
certain tarfile headers. A remote attacker could possibly use this issue
to cause Python to consume resources, leading to a denial of service.
(CVE-2024-6232)
It was discovered that the Python email module incorrectly quoted newlines
for email headers. A remote attacker
OSV
python2.7, python3.5 vulnerability
osv·2024-10-01·CVSS 5.3
CVE-2023-27043 [MEDIUM] python2.7, python3.5 vulnerability
python2.7, python3.5 vulnerability
USN-7015-1 fixed several vulnerabilities in Python. This update provides
the corresponding updates for CVE-2023-27043 for python2.7 in Ubuntu 16.04
LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS, and for
python3.5 in Ubuntu 16.04 LTS.
Original advisory details:
It was discovered that the Python email module incorrectly parsed email
addresses that contain special characters. A remote attacker could
possibly use this issue to bypass certain protection mechanisms.
(CVE-2023-27043)
It was discovered that Python allowed excessive backtracking while parsing
certain tarfile headers. A remote attacker could possibly use this issue
to cause Python to consume resources, leading to a denial of service.
(CVE-2024-6232)
It was discovered that the P
OSV
python2.7, python3.5 vulnerabilities
osv·2024-09-19·CVSS 7.5
[HIGH] python2.7, python3.5 vulnerabilities
python2.7, python3.5 vulnerabilities
USN-7015-1 fixed several vulnerabilities in Python. This update provides
one of the corresponding updates for python2.7 for Ubuntu 16.04 LTS,
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS, and a second for
python3.5 for Ubuntu 16.04 LTS.
Original advisory details:
It was discovered that Python allowed excessive backtracking while
parsing certain tarfile headers. A remote attacker could possibly use
this issue to cause Python to consume resources, leading to a denial
of service. This issue only affected python3.5 for
Ubuntu 16.04 LTS (CVE-2024-6232)
It was discovered that the Python http.cookies module incorrectly
handled parsing cookies that contained backslashes for quoted
characters. A remote attacker could possibly use this issue to ca
OSV
python3.10, python3.12, python3.8 vulnerabilities
osv·2024-09-16·CVSS 5.3
CVE-2023-27043 [MEDIUM] python3.10, python3.12, python3.8 vulnerabilities
python3.10, python3.12, python3.8 vulnerabilities
It was discovered that the Python email module incorrectly parsed email
addresses that contain special characters. A remote attacker could possibly
use this issue to bypass certain protection mechanisms. (CVE-2023-27043)
It was discovered that Python allowed excessive backtracking while parsing
certain tarfile headers. A remote attacker could possibly use this issue to
cause Python to consume resources, leading to a denial of service.
(CVE-2024-6232)
It was discovered that the Python email module incorrectly quoted newlines
for email headers. A remote attacker could possibly use this issue to
perform header injection. (CVE-2024-6923)
It was discovered that the Python http.cookies module incorrectly handled
parsing cookies that contained
OSV
CVE-2024-6232: There is a MEDIUM severity vulnerability affecting CPython
osv·2024-09-03·CVSS 7.5
CVE-2024-6232 [HIGH] CVE-2024-6232: There is a MEDIUM severity vulnerability affecting CPython
There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.
OSV
CVE-2024-6232: There is a MEDIUM severity vulnerability affecting CPython
osv·2024-09-03·CVSS 7.5
CVE-2024-6232 [HIGH] CVE-2024-6232: There is a MEDIUM severity vulnerability affecting CPython
There is a MEDIUM severity vulnerability affecting CPython.
Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.
GHSA
GHSA-mmm5-wgvp-wp8r: There is a MEDIUM severity vulnerability affecting CPython
ghsa_unreviewed·2024-09-03
CVE-2024-6232 [HIGH] CWE-1333 GHSA-mmm5-wgvp-wp8r: There is a MEDIUM severity vulnerability affecting CPython
There is a MEDIUM severity vulnerability affecting CPython.
Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.
Ubuntu
Python 2.7 regression
vendor_ubuntu·2025-09-29·CVSS 5.3
CVE-2023-27043 [MEDIUM] Python 2.7 regression
Title: Python 2.7 regression
Summary: USN-7015-4 introduced a regression in Python 2.7
USN-7015-4 fixed vulnerabilities in Python. It was discovered that the fix
for CVE-2023-27043 for python2.7 was incorrectly applied on Ubuntu 16.04
LTS and Ubuntu 18.04 LTS. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the Python email module incorrectly parsed email
addresses that contain special characters. A remote attacker could
possibly use this issue to bypass certain protection mechanisms.
(CVE-2023-27043)
It was discovered that Python allowed excessive backtracking while parsing
certain tarfile headers. A remote attacker could possibly use this issue
to cause Python to consume resources, leading to a denial of service.
Ubuntu
Python vulnerabilities
vendor_ubuntu·2025-05-06·CVSS 3.7
CVE-2024-11168 [LOW] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that Python incorrectly handled parsing bracketed hosts.
A remote attacker could possibly use this issue to perform a Server-Side
Request Forgery (SSRF) attack. This issue only affected python 2.7 and
python3.4 on Ubuntu 14.04 LTS; python2.7 on Ubuntu 16.04 LTS;
python2.7, python3.6, python3.7, and python3.8 on Ubuntu 18.04 LTS;
python2.7 and python3.9 on Ubuntu 20.04 LTS; and python2.7 and
python3.11 on Ubuntu 22.04 LTS. (CVE-2024-11168)
It was discovered that Python allowed excessive backtracking while
parsing certain tarfile headers. A remote attacker could possibly use
this issue to cause Python to consume excessive resources, leading to
a denial of service. This issue only affecte
Ubuntu
Python regressions
vendor_ubuntu·2024-11-22·CVSS 5.3
CVE-2023-27043 [MEDIUM] Python regressions
Title: Python regressions
Summary: USN-7015-5 caused some regressions in Python.
USN-7015-5 fixed vulnerabilities in python2.7. The update introduced
several minor regressions. This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
It was discovered that the Python email module incorrectly parsed email
addresses that contain special characters. A remote attacker could
possibly use this issue to bypass certain protection mechanisms.
(CVE-2023-27043)
It was discovered that Python allowed excessive backtracking while parsing
certain tarfile headers. A remote attacker could possibly use this issue
to cause Python to consume resources, leading to a denial of service.
(CVE-2024-6232)
It was discovered that the Python email module incorrectly quoted n
Ubuntu
Python vulnerabilities
vendor_ubuntu·2024-11-19·CVSS 5.3
CVE-2024-6232 [MEDIUM] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
USN-7015-1 fixed several vulnerabilities in Python. This update provides
the corresponding update for CVE-2024-6232 and CVE-2024-6923 for python2.7
in Ubuntu 14.04 LTS, Ubuntu 16.04 LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS
and Ubuntu 22.04 LTS.
Original advisory details:
It was discovered that the Python email module incorrectly parsed email
addresses that contain special characters. A remote attacker could
possibly use this issue to bypass certain protection mechanisms.
(CVE-2023-27043)
It was discovered that Python allowed excessive backtracking while parsing
certain tarfile headers. A remote attacker could possibly use this issue
to cause Python to consume resources, leading to a denial of service.
Ubuntu
Python vulnerability
vendor_ubuntu·2024-10-14·CVSS 5.3
CVE-2023-27043 [MEDIUM] Python vulnerability
Title: Python vulnerability
Summary: Python could me made to bypass some restrictions if it received specially
crafted input.
USN-7015-1 fixed several vulnerabilities in Python. This update provides the
corresponding update for CVE-2023-27043 for python2.7 and python3.5 in
Ubuntu 14.04 LTS.
Original advisory details:
It was discovered that the Python email module incorrectly parsed email
addresses that contain special characters. A remote attacker could
possibly use this issue to bypass certain protection mechanisms.
(CVE-2023-27043)
It was discovered that Python allowed excessive backtracking while parsing
certain tarfile headers. A remote attacker could possibly use this issue
to cause Python to consume resources, leading to a denial of service.
(CVE-2024-6232)
It was discovered th
Ubuntu
Python vulnerability
vendor_ubuntu·2024-10-01·CVSS 5.3
CVE-2023-27043 [MEDIUM] Python vulnerability
Title: Python vulnerability
Summary: Python could be made to bypass some restrictions if it received specially
crafted input.
USN-7015-1 fixed several vulnerabilities in Python. This update provides
the corresponding updates for CVE-2023-27043 for python2.7 in Ubuntu 16.04
LTS, Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS, and for
python3.5 in Ubuntu 16.04 LTS.
Original advisory details:
It was discovered that the Python email module incorrectly parsed email
addresses that contain special characters. A remote attacker could
possibly use this issue to bypass certain protection mechanisms.
(CVE-2023-27043)
It was discovered that Python allowed excessive backtracking while parsing
certain tarfile headers. A remote attacker could possibly use this issue
to cause Python to cons
Ubuntu
Python vulnerabilities
vendor_ubuntu·2024-09-19·CVSS 7.5
CVE-2024-6232 [HIGH] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
USN-7015-1 fixed several vulnerabilities in Python. This update provides
one of the corresponding updates for python2.7 for Ubuntu 16.04 LTS,
Ubuntu 18.04 LTS, Ubuntu 20.04 LTS, and Ubuntu 22.04 LTS, and a second for
python3.5 for Ubuntu 16.04 LTS.
Original advisory details:
It was discovered that Python allowed excessive backtracking while
parsing certain tarfile headers. A remote attacker could possibly use
this issue to cause Python to consume resources, leading to a denial
of service. This issue only affected python3.5 for
Ubuntu 16.04 LTS (CVE-2024-6232)
It was discovered that the Python http.cookies module incorrectly
handled parsing cookies that contained backslashes for quoted
characters. A re
Ubuntu
Python vulnerabilities
vendor_ubuntu·2024-09-16·CVSS 5.3
CVE-2024-6923 [MEDIUM] Python vulnerabilities
Title: Python vulnerabilities
Summary: Several security issues were fixed in Python.
It was discovered that the Python email module incorrectly parsed email
addresses that contain special characters. A remote attacker could possibly
use this issue to bypass certain protection mechanisms. (CVE-2023-27043)
It was discovered that Python allowed excessive backtracking while parsing
certain tarfile headers. A remote attacker could possibly use this issue to
cause Python to consume resources, leading to a denial of service.
(CVE-2024-6232)
It was discovered that the Python email module incorrectly quoted newlines
for email headers. A remote attacker could possibly use this issue to
perform header injection. (CVE-2024-6923)
It was discovered that the Python http.cookies module incorrectly ha
Microsoft
Regular-expression DoS when parsing TarFile headers
vendor_msrc·2024-09-10·CVSS 7.5
CVE-2024-6232 [HIGH] CWE-1333 Regular-expression DoS when parsing TarFile headers
Regular-expression DoS when parsing TarFile headers
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
PSF: PSF
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Reference: https://learn.microso
Red Hat
python: cpython: tarfile: ReDos via excessive backtracking while parsing header values
vendor_redhat·2024-09-03·CVSS 7.5
CVE-2024-6232 [HIGH] CWE-1333 python: cpython: tarfile: ReDos via excessive backtracking while parsing header values
python: cpython: tarfile: ReDos via excessive backtracking while parsing header values
There is a MEDIUM severity vulnerability affecting CPython.
Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.
A regular expression denial of service (ReDos) vulnerability was found in Python's tarfile module. Due to excessive backtracking while tarfile parses headers, an attacker may be able to trigger a denial of service via a specially crafted tar archive.
Statement: This vulnerability is classified as moderate severity rather than important because while it does allow for a denial of service (DoS) attack via excessive backtracking in the tarfile module, it does not enable remote code execution
Debian
CVE-2024-6232: pypy3 - There is a MEDIUM severity vulnerability affecting CPython. Regular express...
vendor_debian·2024·CVSS 7.5
CVE-2024-6232 [HIGH] CVE-2024-6232: pypy3 - There is a MEDIUM severity vulnerability affecting CPython. Regular express...
There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.
Scope: local
bookworm: open
bullseye: resolved (fixed in 7.3.5+dfsg-2+deb11u5)
forky: resolved (fixed in 7.3.18+dfsg-1)
sid: resolved (fixed in 7.3.18+dfsg-1)
trixie: resolved (fixed in 7.3.18+dfsg-1)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://github.com/python/cpython/commit/34ddb64d088dd7ccc321f6103d23153256caa5d4https://github.com/python/cpython/commit/4eaf4891c12589e3c7bdad5f5b076e4c8392dd06https://github.com/python/cpython/commit/743acbe872485dc18df4d8ab2dc7895187f062c4https://github.com/python/cpython/commit/7d1f50cd92ff7e10a1c15a8f591dde8a6843a64dhttps://github.com/python/cpython/commit/b4225ca91547aa97ed3aca391614afbb255bc877https://github.com/python/cpython/commit/d449caf8a179e3b954268b3a88eb9170be3c8fbfhttps://github.com/python/cpython/commit/ed3a49ea734ada357ff4442996fd4ae71d253373https://github.com/python/cpython/issues/121285https://github.com/python/cpython/pull/121286https://mail.python.org/archives/list/[email protected]/thread/JRYFTPRHZRTLMZLWQEUHZSJXNHM4ACTY/http://www.openwall.com/lists/oss-security/2024/09/03/5https://lists.debian.org/debian-lts-announce/2024/12/msg00000.htmlhttps://security.netapp.com/advisory/ntap-20241018-0007/
2024-09-03
Published