CVE-2024-6232: Python
High severity, CVSS 7.5. EPSS: 2.2% chance of exploitation in the next 30 days.
There is a MEDIUM severity vulnerability affecting CPython. Regular expressions that allowed excessive backtracking during tarfile.TarFile header parsing are vulnerable to ReDoS via specifically-crafted tar archives.
Affected products
- Python Python: before 3.8.20 (fixed in 3.8.20); from 3.9.0, before 3.9.20 (fixed in 3.9.20); from 3.10.0, before 3.10.15 (fixed in 3.10.15); from 3.11.0, before 3.11.10 (fixed in 3.11.10); from 3.12.0, before 3.12.6 (fixed in 3.12.6); version 3.13.0 only
Published 2024-09-03. Last modified 2026-06-17.