CVE-2020-8492EPSS p93.7%
CVE-2020-8492CVE-2020-8492
python / python
Description
Python 2.7 through 2.7.17, 3.5 through 3.5.9, 3.6 through 3.6.10, 3.7 through 3.7.6, and 3.8 through 3.8.1 allows an HTTP server to conduct Regular Expression Denial of Service (ReDoS) attacks against a client because of urllib.request.AbstractBasicAuthHandler catastrophic backtracking.
Scoring
| CVSS | 6.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H |
| EPSS | 6.62% probability of exploitation · percentile 93.7% · 2026-10-10T12:00:23Z |
| Last modified | 2026-10-07 |