PT-2022-4709 · Python+10 · Python+10

Published

2022-09-02

·

Updated

2025-11-26

·

CVE-2020-10735

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Python (affected versions not specified)
Description A flaw was found in Python related to errors in converting data types between int and str. This issue is associated with algorithms that have quadratic time complexity and use non-binary bases. When using int("text"), a system could take a significant amount of time to parse an int string, for example, 50ms for a string with 100,000 digits and 5s for a string with 1,000,000 digits. The float, decimal, int.from bytes(), and int() functions for binary bases 2, 4, 8, 16, and 32 are not affected. This vulnerability poses the highest threat to system availability, as it could allow an attacker to cause a denial of service by consuming all available resources.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Incorrect Type Conversion or Cast

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2022:7323
ALSA-2023:0833
ALSA-2023:2763
ALSA-2023:2764
ALT-PU-2022-2599
ALT-PU-2023-1518
ALT-PU-2023-7318
ALT-PU-2023-7463
ALT-PU-2023-7647
ALT-PU-2023-7888
ALT-PU-2024-2598
ALT-PU-2024-3474
BDU:2022-05599
BIT-LIBPYTHON-2020-10735
BIT-PYTHON-2020-10735
BIT-PYTHON-MIN-2020-10735
CESA-2023_0833
CESA-2023_2763
CESA-2023_2764
CVE-2020-10735
DLA-3477-1
DLA-3966-1
DLA-3980-1
MGASA-2022-0359
OESA-2022-1921
OPENSUSE-SU-2022_3473-1
OPENSUSE-SU-2022_3485-1
OPENSUSE-SU-2022_4281-1
OPENSUSE-SU-2024:12318-1
OPENSUSE-SU-2024:12336-1
OPENSUSE-SU-2024:12340-1
OPENSUSE-SU-2024:12341-1
OPENSUSE-SU-2024:12342-1
OPENSUSE-SU-2024:12910-1
OPENSUSE-SU-2024:14109-1
OPENSUSE-SU-2024:14434-1
OPENSUSE-SU-2025:14712-1
OPENSUSE-SU-2025:15713-1
PSF-2022-4
RHSA-2022:6766
RHSA-2022:7323
RHSA-2022_7323
RHSA-2023:0833
RHSA-2023:2763
RHSA-2023:2764
RHSA-2023_0833
RHSA-2023_2763
RHSA-2023_2764
RHSA-2024:0430
RLSA-2022:7323
RLSA-2023:0833
ROSA-SA-2025-2676
SUSE-SU-2022:3473-1
SUSE-SU-2022:3485-1
SUSE-SU-2022:3924-1
SUSE-SU-2022:4251-1
SUSE-SU-2022:4274-1
SUSE-SU-2022:4281-1
SUSE-SU-2022_3473-1
SUSE-SU-2022_3485-1
SUSE-SU-2022_3924-1
SUSE-SU-2022_4251-1
SUSE-SU-2022_4274-1

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Debian
Ibm Aix
Python
Red Hat
Red Os
Rocky Linux
Suse