---
id: CVE-2010-3198
aliases:
  - PYSEC-2010-32
  - GHSA-qh4q-fwf8-qqrw
  - PYSEC-2010-33
title: >-
  ZServer in Zope 2.10.x before 2.10.12 and 2.11.x before 2.11.7 allows remote
  attackers to cause a denial of service (crash of worker thre…
summary: >-
  ZServer in Zope 2.10.x before 2.10.12 and 2.11.x before 2.11.7 allows remote
  attackers to cause a denial of service (crash of worker threads) via vectors
  that trigger uncaught exceptions.
severity: none
vendor: zope
product: zope
ecosystem: pip
affected:
  - 'zope >= 2.11.0, < 2.11.7'
patched:
  - zope 2.11.7
published: '2010-09-08'
updated: '2026-07-01'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/PYSEC-2010-32'
references:
  - url: 'https://mail.zope.org/pipermail/zope-announce/2010-September/002247.html'
  - url: 'https://mail.zope.org/pipermail/zope-announce/2010-September/002247.html'
  - url: 'http://www.zope.org/Products/Zope/2.10.12/CHANGES.txt'
  - url: 'http://www.vupen.com/english/advisories/2010/2275'
  - url: 'http://www.securityfocus.com/bid/42939'
  - url: 'http://www.zope.org/Products/Zope/2.11.7/CHANGES.txt'
  - url: 'https://bugs.launchpad.net/zope2/+bug/627988'
  - url: 'https://bugs.launchpad.net/zope2/+bug/627988'
  - url: 'https://bugs.launchpad.net/zope2/+bug/627988'
tags:
  - osv
  - pip
epss: 0.01541
epssPercentile: 0.73395
ingestedAt: '2026-07-08T18:25:55.314Z'
---

## Overview

ZServer in Zope 2.10.x before 2.10.12 and 2.11.x before 2.11.7 allows remote attackers to cause a denial of service (crash of worker threads) via vectors that trigger uncaught exceptions.

## Affected packages

- `zope >= 2.11.0, < 2.11.7`

## Remediation

Upgrade to a patched release:

- `zope 2.11.7`
