CVE-2012-1150: Python

Medium severity, CVSS 5.0. EPSS: 5.1% chance of exploitation in the next 30 days.

Python before 2.6.8, 2.7.x before 2.7.3, 3.x before 3.1.5, and 3.2.x before 3.2.3 computes hash values without restricting the ability to trigger hash collisions predictably, which allows context-dependent attackers to cause a denial of service (CPU consumption) via crafted input to an application that maintains a hash table.

Affected products

  • Python Python: up to and including 2.6.7; version 0.9.0 only; version 0.9.1 only; version 1.2 only; version 1.3 only; version 1.5.2 only; …

Published 2012-10-05. Last modified 2026-06-16.