CVE-2024-0397: Python Software Foundation Cpython

High severity, CVSS 7.4. EPSS: 0.8% chance of exploitation in the next 30 days.

A defect was discovered in the Python “ssl” module where there is a memory race condition with the ssl.SSLContext methods “cert_store_stats()” and “get_ca_certs()”. The race condition can be triggered if the methods are called at the same time as certificates are loaded into the SSLContext, such as during the TLS handshake with a certificate directory configured. This issue is fixed in CPython 3.10.14, 3.11.9, 3.12.3, and 3.13.0a5.

Affected products

  • Python Software Foundation Cpython: before 3.8.20 (fixed in 3.8.20); from 3.9.0, before 3.9.20 (fixed in 3.9.20); from 3.10.0, before 3.10.14 (fixed in 3.10.14); from 3.11.0, before 3.11.9 (fixed in 3.11.9); from 3.12.0, before 3.12.3 (fixed in 3.12.3); from 3.13.0a1, before 3.13.0a5 (fixed in 3.13.0a5)

Published 2024-06-17. Last modified 2026-06-17.