{"id":"CVE-2020-8492","title":"Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.A…","summary":"Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.A…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":["CWE-400"],"vendor":"python","product":"python","affected":["python >= 2.7.0, <= 2.7.17","python >= 3.5.0, <= 3.5.9","python >= 3.6.0, <= 3.6.10","python >= 3.7.0, <= 3.7.6","python >= 3.8.0, <= 3.8.1","leap = 15.1","ubuntu_linux = 12.04","ubuntu_linux = 14.04","ubuntu_linux = 16.04","ubuntu_linux = 18.04","ubuntu_linux = 19.10","ubuntu_linux = 20.04","fedora = 31","fedora = 32","debian_linux = 9.0"],"published":"2020-01-30","updated":"2026-10-07","sourceUpdated":"2026-10-07T19:17:18.690","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2020-8492","references":[{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00003.html","label":"cve@mitre.org"},{"url":"https://bugs.python.org/issue39503","label":"cve@mitre.org"},{"url":"https://github.com/python/cpython/pull/18284","label":"cve@mitre.org"},{"url":"https://lists.apache.org/thread.html/rdb31a608dd6758c6093fd645aea3fbf022dd25b37109b6aaea5bc0b5%40%3Ccommits.cassandra.apache.org%3E","label":"cve@mitre.org"},{"url":"https://lists.apache.org/thread.html/rfec113c733162b39633fd86a2d0f34bf42ac35f711b3ec1835c774da%40%3Ccommits.cassandra.apache.org%3E","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","label":"cve@mitre.org"},{"url":"https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WOKDEXLYW5UQ4S7PA7E37IITOC7C56J/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A5NSAX4SC3V64PGZUPH7PRDLSON34Q5A/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APGWEMYZIY5VHLCSZ3HD67PA5Z2UQFGH/","label":"cve@mitre.org"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UESGYI5XDAHJBATEZN3MHNDUBDH47AS6/","label":"cve@mitre.org"},{"url":"https://python-security.readthedocs.io/vuln/urllib-basic-auth-regex.html","label":"cve@mitre.org"},{"url":"https://security.gentoo.org/glsa/202005-09","label":"cve@mitre.org"},{"url":"https://security.netapp.com/advisory/ntap-20200221-0001/","label":"cve@mitre.org"},{"url":"https://usn.ubuntu.com/4333-1/","label":"cve@mitre.org"},{"url":"https://usn.ubuntu.com/4333-2/","label":"cve@mitre.org"},{"url":"http://lists.opensuse.org/opensuse-security-announce/2020-03/msg00003.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://bugs.python.org/issue39503","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://github.com/python/cpython/pull/18284","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rdb31a608dd6758c6093fd645aea3fbf022dd25b37109b6aaea5bc0b5%40%3Ccommits.cassandra.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.apache.org/thread.html/rfec113c733162b39633fd86a2d0f34bf42ac35f711b3ec1835c774da%40%3Ccommits.cassandra.apache.org%3E","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2020/07/msg00011.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.debian.org/debian-lts-announce/2023/05/msg00024.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/7WOKDEXLYW5UQ4S7PA7E37IITOC7C56J/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/A5NSAX4SC3V64PGZUPH7PRDLSON34Q5A/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/APGWEMYZIY5VHLCSZ3HD67PA5Z2UQFGH/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/UESGYI5XDAHJBATEZN3MHNDUBDH47AS6/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://python-security.readthedocs.io/vuln/urllib-basic-auth-regex.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.gentoo.org/glsa/202005-09","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20200221-0001/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4333-1/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://usn.ubuntu.com/4333-2/","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"epss":0.06617,"epssPercentile":0.93675,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-10-07T18:07:08.805022Z"},"ingestedAt":"2026-10-07T18:42:20.905Z","slug":"CVE-2020-8492","body":"## Overview\n\nPython 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.\n\n## Affected\n\n- `python >= 2.7.0, <= 2.7.17`\n- `python >= 3.5.0, <= 3.5.9`\n- `python >= 3.6.0, <= 3.6.10`\n- `python >= 3.7.0, <= 3.7.6`\n- `python >= 3.8.0, <= 3.8.1`\n- `leap = 15.1`\n- `ubuntu_linux = 12.04`\n- `ubuntu_linux = 14.04`\n- `ubuntu_linux = 16.04`\n- `ubuntu_linux = 18.04`\n- `ubuntu_linux = 19.10`\n- `ubuntu_linux = 20.04`\n- `fedora = 31`\n- `fedora = 32`\n- `debian_linux = 9.0`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":35.8,"likelihood":1.3,"exploitation":0,"ransomware":0},"changes":[]}