CVE-2014-4650: Python

Critical severity, CVSS 9.8. EPSS: 24.7% chance of exploitation in the next 30 days.

The CGIHTTPServer module in Python 2.7.5 and 3.3.4 does not properly handle URLs in which URL encoding is used for path separators, which allows remote attackers to read script source code or conduct directory traversal attacks and execute unintended code via a crafted character sequence, as demonstrated by a %2f separator.

Affected products

  • Python Python: from 2.7.0, before 2.7.8 (fixed in 2.7.8); from 3.2.0, before 3.2.6 (fixed in 3.2.6); from 3.3.0, before 3.3.6 (fixed in 3.3.6); from 3.4.0, before 3.4.2 (fixed in 3.4.2)
  • Red Hat Enterprise Linux: version 5.0 only; version 6.0 only; version 7.0 only
  • Red Hat Software Collections: affected versions not specified

Published 2020-02-20. Last modified 2026-06-17.