Bugzilla – Bug 1206673
VUL-0: CVE-2022-40899: python,python39,python3,python310,python36,python27,python-future: ReDos in python-future and some cpython versions
Last modified: 2025-11-24 17:40:16 UTC
CVE-2022-40899 An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2022-40899 https://www.cve.org/CVERecord?id=CVE-2022-40899 https://github.com/python/cpython/pull/17157 https://github.com/PythonCharmers/python-future/blob/master/src/future/backports/http/cookiejar.py#L215 http://www.cvedetails.com/cve/CVE-2022-40899/ https://pypi.org/project/future/ https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages/
Fix: https://github.com/python/cpython/pull/17157 python-future does not have this upstream fix yet (unclear if the project is abandoned or not), but the patch should be the same as for cpython Affected python2: - SUSE:SLE-11-SP1:Update/python 2.6.9 Affected python3: - SUSE:SLE-12:Update/python3 3.4.10 Affected python-future: - SUSE:SLE-12:Update/python-future 0.15.2 - SUSE:SLE-12-SP2:Update/python-future 0.15.2 - SUSE:SLE-15:Update/python-future 0.16.0 - SUSE:SLE-15-SP3:Update/python-future 0.18.2 - openSUSE:Factory/python-future 0.18.2 Not Affected: - SUSE:SLE-11-SP1:Update:Teradata/python27 2.7.18 - SUSE:SLE-12-SP1:Update/python 2.7.18 - SUSE:SLE-12-SP4:Update/python 2.7.18 - SUSE:SLE-15:Update/python 2.7.18 - openSUSE:Factory/python 2.7.18 - SUSE:Carwos:1/python3 3.6.15 - SUSE:SLE-12-SP3:Update:Products:Teradata:Update/python36 3.6.15 - SUSE:SLE-12-SP5:Update/python36 3.6.15 - SUSE:SLE-15-SP3:Update/python3 3.6.15 - SUSE:SLE-15:Update/python3 3.6.15 - SUSE:SLE-15-SP3:Update/python39 3.9.15 - openSUSE:Factory/python39 3.9.16 - SUSE:SLE-15-SP4:Update/python310 3.10.8 - openSUSE:Factory/python310 3.10.9
This is an autogenerated message for OBS integration: This bug (1206673) was mentioned in https://build.opensuse.org/request/show/1056169 Factory / python-future
I've created a Request with with a patch for each affected version of python-future and cpython.
SUSE-SU-2023:0076-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1206673 CVE References: CVE-2022-40899 JIRA References: Sources used: SUSE Linux Enterprise Software Development Kit 12-SP5 (src): python3-3.4.10-25.105.1, python3-base-3.4.10-25.105.1 SUSE Linux Enterprise Server 12-SP5 (src): python3-3.4.10-25.105.1, python3-base-3.4.10-25.105.1 SUSE Linux Enterprise Module for Web Scripting 12 (src): python3-3.4.10-25.105.1, python3-base-3.4.10-25.105.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2023:0078-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1206673 CVE References: CVE-2022-40899 JIRA References: Sources used: SUSE Linux Enterprise Module for Public Cloud 12 (src): python-future-0.15.2-3.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2023:0079-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1206673 CVE References: CVE-2022-40899 JIRA References: Sources used: openSUSE Leap Micro 5.3 (src): python-future-0.18.2-150300.3.3.1 openSUSE Leap Micro 5.2 (src): python-future-0.18.2-150300.3.3.1 openSUSE Leap 15.4 (src): python-future-0.18.2-150300.3.3.1 SUSE Linux Enterprise Realtime Extension 15-SP3 (src): python-future-0.18.2-150300.3.3.1 SUSE Linux Enterprise Module for Basesystem 15-SP4 (src): python-future-0.18.2-150300.3.3.1 SUSE Linux Enterprise Micro 5.3 (src): python-future-0.18.2-150300.3.3.1 SUSE Linux Enterprise Micro 5.2 (src): python-future-0.18.2-150300.3.3.1 SUSE Linux Enterprise Micro 5.1 (src): python-future-0.18.2-150300.3.3.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2023:0080-1: An update that fixes one vulnerability is now available. Category: security (moderate) Bug References: 1206673 CVE References: CVE-2022-40899 JIRA References: Sources used: SUSE Linux Enterprise Server 12-SP5 (src): python-future-0.15.2-3.5.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
SUSE-SU-2023:0663-1: An update that solves two vulnerabilities can now be installed. Category: security (important) Bug References: 1206673, 1208471 CVE References: CVE-2022-40899, CVE-2023-24329 Sources used: SUSE OpenStack Cloud 9 (src): python3-base-3.4.10-25.108.1, python3-3.4.10-25.108.1 SUSE OpenStack Cloud Crowbar 9 (src): python3-base-3.4.10-25.108.1, python3-3.4.10-25.108.1 Web and Scripting Module 12 (src): python3-base-3.4.10-25.108.1, python3-3.4.10-25.108.1 SUSE Linux Enterprise Server for SAP Applications 12 SP4 (src): python3-base-3.4.10-25.108.1, python3-3.4.10-25.108.1 SUSE Linux Enterprise Software Development Kit 12 SP5 (src): python3-base-3.4.10-25.108.1, python3-3.4.10-25.108.1 SUSE Linux Enterprise Server 12 SP2 BCL 12-SP2 (src): python3-base-3.4.10-25.108.1, python3-3.4.10-25.108.1 SUSE Linux Enterprise Server 12 SP4 ESPOS 12-SP4 (src): python3-base-3.4.10-25.108.1, python3-3.4.10-25.108.1 SUSE Linux Enterprise Server 12 SP4 LTSS 12-SP4 (src): python3-base-3.4.10-25.108.1, python3-3.4.10-25.108.1 SUSE Linux Enterprise High Performance Computing 12 SP5 (src): python3-base-3.4.10-25.108.1, python3-3.4.10-25.108.1 SUSE Linux Enterprise Server 12 SP5 (src): python3-base-3.4.10-25.108.1, python3-3.4.10-25.108.1 SUSE Linux Enterprise Server for SAP Applications 12 SP5 (src): python3-base-3.4.10-25.108.1, python3-3.4.10-25.108.1 NOTE: This line indicates an update has been released for the listed product(s). At times this might be only a partial fix. If you have questions please reach out to maintenance coordination.
done, closing