CVE-2024-6232
There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.
- Python
- < 3.8.20, 3.9.20, 3.10.15, 3.11.10, 3.12.6, 3.13.0
- CVSS 3.1
- 7.5 HIGH
- EPSS
- 2.2% (81th percentile)
- Weakness
- CWE-1333
- NVD status
- Modified
- Published
- 2024-09-03
CVE-2024-6232 at NVD
1 known exploit for CVE-2024-6232
Proof-of-concept code and exploit modules indexed by Sploitus