Skip to content

Commit 9df584a

Browse files
committed
Add News for new CVE
1 parent 8de1ece commit 9df584a

File tree

1 file changed

+10
-0
lines changed

1 file changed

+10
-0
lines changed

Misc/NEWS.d/2.7.18.10.rst

Lines changed: 10 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -41,3 +41,13 @@ CVE-2024-0397 Fix locking in cert_store_stats and get_ca_certs
4141
:meth:`ssl.SSLContext.get_ca_certs` now correctly lock access to the
4242
certificate store, when the :class:`ssl.SSLContext` is shared across
4343
multiple threads.
44+
45+
.. gh: 123067
46+
.. date: 2024-08-22
47+
.. nonce:
48+
.. release date: 2024-08-22
49+
.. section: Core and Builtins
50+
51+
CVE-2024-7592 Fix quadratic complexity in parsing quoted cookie
52+
53+
Fix quadratic complexity in parsing ``"``-quoted cookie values with backslashes by :mod:`http.cookies`.

0 commit comments

Comments
 (0)