id: PYSEC-2022-42991 details: An issue discovered in Python Charmers Future 0.18.2 and earlier allows remote attackers to cause a denial of service via crafted Set-Cookie header from malicious web server. affected: - package: name: future ecosystem: PyPI purl: pkg:pypi/future ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 0.18.3 versions: - 0.0.1 - 0.0.2 - 0.0.3 - 0.1.0 - 0.10.0 - 0.10.1 - 0.10.2 - 0.11.0 - 0.11.1 - 0.11.2 - 0.11.3 - 0.11.4 - 0.12.0 - 0.12.1 - 0.12.2 - 0.12.3 - 0.12.4 - 0.13.0 - 0.13.1 - 0.14.0 - 0.14.1 - 0.14.2 - 0.14.3 - 0.15.0 - 0.15.1 - 0.15.2 - 0.16.0 - 0.17.0 - 0.17.1 - 0.18.0 - 0.18.1 - 0.18.2 - 0.2.0 - 0.3.0 - 0.3.1 - 0.3.2 - 0.3.3 - 0.3.4 - 0.3.5 - 0.4.0 - 0.4.1 - 0.5.0 - 0.5.1 - 0.5.2 - 0.6.0 - 0.7.0 - 0.8.0 - 0.8.1 - 0.8.2 - 0.9.0 references: - type: PACKAGE url: https://pypi.org/project/future/ - type: EVIDENCE url: https://github.com/python/cpython/pull/17157 - type: FIX url: https://github.com/python/cpython/pull/17157 - type: WEB url: https://github.com/python/cpython/pull/17157 - type: WEB url: https://github.com/PythonCharmers/python-future/blob/master/src/future/backports/http/cookiejar.py#L215 - type: EVIDENCE url: https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages/ - type: ADVISORY url: https://pyup.io/posts/pyup-discovers-redos-vulnerabilities-in-top-python-packages/ - type: WEB url: https://github.com/PythonCharmers/python-future/pull/610 - type: ADVISORY url: https://github.com/advisories/GHSA-v3c5-jqr6-7qm8 aliases: - CVE-2022-40899 - GHSA-v3c5-jqr6-7qm8 modified: "2023-05-04T03:49:45.660760Z" published: "2022-12-23T00:15:00Z"