CVE-2020-10735: Fedoraproject Fedora

High severity, CVSS 7.5. EPSS: 4.5% chance of exploitation in the next 30 days.

A flaw was found in python. In algorithms with quadratic time complexity using non-binary bases, when using int("text"), a system could take 50ms to parse an int string with 100,000 digits and 5s for 1,000,000 digits (float, decimal, int.from_bytes(), and int() for binary bases 2, 4, 8, 16, and 32 are not affected). The highest threat from this vulnerability is to system availability.

Affected products

  • Fedoraproject Fedora: version 35 only; version 36 only; version 37 only
  • Python Python: from 3.7.0, before 3.7.14 (fixed in 3.7.14); from 3.8.0, before 3.8.14 (fixed in 3.8.14); from 3.9.0, before 3.9.14 (fixed in 3.9.14); from 3.10.0, before 3.10.7 (fixed in 3.10.7); version 3.11.0 only
  • Red Hat Enterprise Linux: version 8.0 only
  • Red Hat Quay: version 3.0.0 only
  • Red Hat Software Collections: affected versions not specified

Published 2022-09-09. Last modified 2026-10-07.