CVE-2024-3219: Python Software Foundation Cpython

Medium severity, CVSS 5.1. EPSS: 0.2% chance of exploitation in the next 30 days.

The “socket” module provides a pure-Python fallback to the socket.socketpair() function for platforms that don’t support AF_UNIX, such as Windows. This pure-Python implementation uses AF_INET or AF_INET6 to create a local connected pair of sockets. The connection between the two sockets was not verified before passing the two sockets back to the user, which leaves the server socket vulnerable to a connection race from a malicious local peer. Platforms that support AF_UNIX such as Linux and macOS are not affected by this vulnerability. Versions prior to CPython 3.5 are not affected due to the vulnerable API not being included.

Affected products

  • Python Software Foundation Cpython: before 3.8.20 (fixed in 3.8.20); from 3.9.0, before 3.9.20 (fixed in 3.9.20); from 3.10.0, before 3.10.15 (fixed in 3.10.15); from 3.11.0, before 3.11.10 (fixed in 3.11.10); from 3.12.0, before 3.12.5 (fixed in 3.12.5); from 3.13.0a1, before 3.13.0rc1 (fixed in 3.13.0rc1)

Published 2024-07-29. Last modified 2026-06-17.